CVE-2020-6923: GHSL-2020-074, 077, 078: Memory corruptions in HPLIP - CVE-2020-6923
HPLIP contains two memory corruption vulnerabilities which can be triggered by a malicious device or computer that is connected to the same network. The vulnerabilities are triggered when an application such as simple-scan searches the network for scanners. In the specific case of simple-scan, this happens immediately when simple-scan starts, so there isn’t even any need to trick the user into thinking that the scanner is genuine so that they will click on it.
Other sources
The HP Linux Imaging and Printing (HPLIP) software may potentially be affected by memory buffer overflow.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6923?
CVE-2020-6923 is classified as a high severity vulnerability due to its potential for memory buffer overflow.
How do I fix CVE-2020-6923?
To fix CVE-2020-6923, update the HPLIP package to a version that is not affected, such as 3.21.2+dfsg1-2 or higher.
What software is affected by CVE-2020-6923?
CVE-2020-6923 affects specific versions of the HP Linux Imaging and Printing (HPLIP) software.
Is there a workaround for CVE-2020-6923?
Currently, the best approach to mitigate CVE-2020-6923 is to update to a patched version of the HPLIP software.
What specific versions of HPLIP are vulnerable to CVE-2020-6923?
The vulnerable versions of HPLIP include 3.22.10+dfsg0-2 and 3.22.10+dfsg0-5.1, among others.