REDHAT-BUG-2480300: Integer Overflow
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
HP Linux Imaging and Printing Software (hplip/hpcups)from your environment.Uninstall the HP Linux Imaging and Printing Software or remove the hpcups backend if printer functionality is not required in order to eliminate the vulnerable processing path.
- Configuration
Disable the hpcups backend or stop the hplip printing service until a vendor patch is available to mitigate processing of crafted print data.
hpcups (HP Linux Imaging and Printing Software) enabled = false - Compensating control
Restrict access to printing services by firewall/ACLs or network segmentation (limit print-server and printer access to trusted hosts/VLANs and require authenticated submission) to prevent untrusted sources from sending crafted print data.
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2480300?
The severity of REDHAT-BUG-2480300 is classified as high, with a score of 7.
What is the potential impact of REDHAT-BUG-2480300?
REDHAT-BUG-2480300 may allow escalation of privileges and/or arbitrary code execution due to an integer overflow.
How do I fix REDHAT-BUG-2480300?
To fix REDHAT-BUG-2480300, you should apply the latest patches or updates provided by HP for the HPLIP software.
Is there a workaround for REDHAT-BUG-2480300?
Currently, there are no specific workarounds for REDHAT-BUG-2480300 other than applying security updates.
Which software is affected by REDHAT-BUG-2480300?
REDHAT-BUG-2480300 affects the HP Linux Imaging and Printing Software (HPLIP) from HP.