PT-2013-1082 · Hewlett Packard+3 · Hplip+3

Raphael Geissert

·

Published

2013-03-06

·

Updated

2024-06-15

·

CVE-2013-6402

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HP Linux Imaging and Printing (HPLIP) versions through 3.13.11
Description The issue concerns multiple vulnerabilities in the HPLIP package of the Debian GNU/Linux operating system. These vulnerabilities can be exploited by a local attacker, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Specifically, the base/pkit.py file in HPLIP is vulnerable to a symlink attack, allowing local users to overwrite arbitrary files via the /tmp/hp-pkservice.log temporary file.
Recommendations For HPLIP versions through 3.13.11, consider restricting access to the base/pkit.py file to prevent exploitation until a patch is available. As a temporary workaround, avoid using the hp-pkservice.log temporary file in the /tmp directory to minimize the risk of arbitrary file overwrites. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1475
BDU:2015-02622
CVE-2013-6402
DSA-2829-1
MGASA-2014-0033
OPENSUSE-SU-2024:10083-1

Affected Products

Alt Linux
Debian
Hplip
Suse