PT-2009-2816 · Hewlett Packard · Hplip

Matt Zimmerman

+1

·

Published

2009-01-15

·

Updated

2009-01-31

·

CVE-2009-0122

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HP Linux Imaging and Printing (HPLIP) versions 2.7.7 through 2.8.2
Description The issue allows local users to change the ownership of arbitrary files via manipulations before an HPLIP installation or upgrade by an administrator. This is related to the product's attempt to correct the ownership of its configuration files within home directories.
Recommendations For HP Linux Imaging and Printing (HPLIP) versions 2.7.7 through 2.8.2, consider restricting access to the hplip.postinst script until a patch is available. As a temporary workaround, avoid running the HPLIP installation or upgrade as an administrator until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0122

Affected Products

Hplip