CVE-2012-6108: Low severity hp linux imaging and printing vulnerability
HP Linux Imaging and Printing (HPLIP) before 3.13.2 uses world-writable permissions for /var/log/hp and /var/log/hp/tmp, which allows local users to delete log files via standard filesystem operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6108?
CVE-2012-6108 is considered a medium severity vulnerability due to its potential for local privilege escalation by allowing users to delete important log files.
How do I fix CVE-2012-6108?
To fix CVE-2012-6108, update the HP Linux Imaging and Printing (HPLIP) software to version 3.13.2 or later, which restricts permissions on the relevant log directories.
What are the risks associated with CVE-2012-6108?
The risks associated with CVE-2012-6108 include unauthorized log file deletions, which can hinder auditing and troubleshooting efforts.
Which versions of HPLIP are affected by CVE-2012-6108?
CVE-2012-6108 affects all versions of HP Linux Imaging and Printing (HPLIP) prior to 3.13.2.
Can CVE-2012-6108 be exploited remotely?
CVE-2012-6108 cannot be exploited remotely as it requires local user access to the affected system.