CVE-2013-6402: Low severity HP Linux Imaging and Printing Project vulnerability
base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.11 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hp-pkservice.log temporary file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/hplipto a version that resolves this vulnerability.Fixed in 3.21.2+dfsg1-2Fixed in 3.22.10+dfsg0-2Fixed in 3.22.10+dfsg0-8.1Fixed in 3.26.4+dfsg0-2
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6402?
CVE-2013-6402 has a moderate severity level due to the potential for local file overrides.
How do I fix CVE-2013-6402?
To fix CVE-2013-6402, upgrade to a version of HP Linux Imaging and Printing newer than 3.13.11.
Which versions of HP Linux Imaging and Printing are affected by CVE-2013-6402?
HP Linux Imaging and Printing versions up to and including 3.13.11 are affected by CVE-2013-6402.
What kind of attack is possible with CVE-2013-6402?
CVE-2013-6402 allows local users to perform a symlink attack, potentially overwriting arbitrary files.
Is CVE-2013-6402 a remote or local vulnerability?
CVE-2013-6402 is a local vulnerability, requiring access to the affected system to exploit.