CVE-2013-0200: Low severity hp linux imaging and printing vulnerability
HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc#.bmp, (2) /tmp/hpcupsfilterk#.bmp, (3) /tmp/hpcupsjob#.out, (4) /tmp/hpijs#####.out, or (5) /tmp/hppsjob#.out temporary file, a different vulnerability than CVE-2011-2722.
Other sources
Temporary file handling flaws were found in several places in hplip. Because a predicatable temporary filenames are used, an attacker could use a symlink attack to overwrite an arbitrary file with the privileges of the process running hplip.
This is a different flaw than CVE-2011-2722.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0200?
CVE-2013-0200 is classified as a medium severity vulnerability that allows local users to overwrite arbitrary files.
How do I fix CVE-2013-0200?
To fix CVE-2013-0200, update HP Linux Imaging and Printing to version 3.12.5 or later.
What systems are affected by CVE-2013-0200?
CVE-2013-0200 affects various versions of HP Linux Imaging and Printing, specifically all versions up to and including 3.12.4.
What type of attack is CVE-2013-0200 associated with?
CVE-2013-0200 is associated with a symlink attack that can lead to file overwriting.
Who can exploit CVE-2013-0200?
CVE-2013-0200 can be exploited by local users who have access to the affected system.