PT-2008-4377 · Hewlett Packard+1 · Hplip+1
Marc Schoenefeld
·
Published
2008-08-12
·
Updated
2017-09-29
·
CVE-2008-2940
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
HPLIP version 1.6.7
Description
The issue in HPLIP allows local users to gain privileges and send e-mail messages from the root account. This is due to vectors related to the setalerts message and the lack of validation of the device URI associated with an event message.
Recommendations
For HPLIP version 1.6.7, consider restricting access to the setalerts message and validating the device URI associated with event messages to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hplip
Red Hat