PT-2008-4377 · Hewlett Packard+1 · Hplip+1

Marc Schoenefeld

·

Published

2008-08-12

·

Updated

2017-09-29

·

CVE-2008-2940

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HPLIP version 1.6.7
Description The issue in HPLIP allows local users to gain privileges and send e-mail messages from the root account. This is due to vectors related to the setalerts message and the lack of validation of the device URI associated with an event message.
Recommendations For HPLIP version 1.6.7, consider restricting access to the setalerts message and validating the device URI associated with event messages to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2940
RHSA-2008:0818
RHSA-2008_0818

Affected Products

Hplip
Red Hat