CVE-2008-2940: High severity hp linux imaging and printing vulnerability
Published Jul 14, 2008
·Updated
The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message.
Affected Software
1 affected component
HP Linux Imaging and Printing Project=1.6.7
Event History
Jul 14, 2008
Data Sourced
10:26 AM
DescriptionSeverityAffected Software
Aug 14, 2008
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2940?
CVE-2008-2940 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2008-2940?
Fix CVE-2008-2940 by upgrading to a patched version of HP Linux Imaging and Printing beyond 1.6.7.
3
Who is affected by CVE-2008-2940?
Local users of HP Linux Imaging and Printing version 1.6.7 are affected by CVE-2008-2940.
4
What kind of attack vector is associated with CVE-2008-2940?
CVE-2008-2940 allows local users to gain privileges through the alert-mailing implementation.
5
What is the main issue with CVE-2008-2940?
The main issue with CVE-2008-2940 is the lack of validation of the device URI in the setalerts message.