PT-2025-26812 · Hewlett Packard · Hp Ipp
Published
2025-06-25
·
Updated
2025-06-30
·
CVE-2024-51979
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
HP IPP versions (affected versions not specified)
Description:
An authenticated attacker can trigger a stack-based buffer overflow by sending a malformed request to the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631). The malformed request contains an empty
Origin header value and a malformed Referer header value. The Referer header value triggers a stack-based buffer overflow when the host value in the Referer header is processed and has a length greater than 64 bytes.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp Ipp