PT-2013-1082 · Hewlett Packard+3 · Hplip+3
Raphael Geissert
·
Publicado
2013-03-06
·
Atualizado
2024-06-15
·
CVE-2013-6402
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
HP Linux Imaging and Printing (HPLIP) versions through 3.13.11
Description
The issue concerns multiple vulnerabilities in the HPLIP package of the Debian GNU/Linux operating system. These vulnerabilities can be exploited by a local attacker, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Specifically, the
base/pkit.py file in HPLIP is vulnerable to a symlink attack, allowing local users to overwrite arbitrary files via the /tmp/hp-pkservice.log temporary file.Recommendations
For HPLIP versions through 3.13.11, consider restricting access to the
base/pkit.py file to prevent exploitation until a patch is available. As a temporary workaround, avoid using the hp-pkservice.log temporary file in the /tmp directory to minimize the risk of arbitrary file overwrites. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Debian
Hplip
Suse