PT-2007-7496 · Hewlett Packard+2 · Hplip-Doc+7

Kees

+1

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2007-5208

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions hplip versions 1.x through 2.x before 2.7.10 hplip-data (affected versions not specified) hpijs-ppds (affected versions not specified) hplip-doc (affected versions not specified) hplip-dbg (affected versions not specified) hpijs (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the hplip package and its related components in Debian GNU/Linux, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The hpssd component in hplip is specifically vulnerable to context-dependent attacks, allowing the execution of arbitrary commands via shell metacharacters in a from address when invoking sendmail.
Recommendations For hplip versions 1.x through 2.x before 2.7.10, update to version 2.7.10 or later. For hplip-data, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For hpijs-ppds, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For hplip-doc, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For hplip-dbg, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For hpijs, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02620
BDU:2015-02621
BDU:2015-02623
BDU:2015-02624
BDU:2015-02625
CVE-2007-5208
DSA-1462-1
DTSA-72-1
OPENSUSE-SU-2024:10847-1
RHSA-2007:0960
RHSA-2007_0960

Affected Products

Debian
Red Hat
Hpijs
Hpijs-Ppds
Hplip
Hplip-Data
Hplip-Dbg
Hplip-Doc