First published: Mon Dec 13 2010(Updated: )
Sebastian Krahmer reported a flaw in how hplip discovered SNMP devices. If certain hplip commands were run that queried SNMP devices, and a malicious user were able to send crafted SNMP responses, it could cause the running hplip tool to crash or, possibly, execute arbitrary code with the privileges of the user running the tool. Acknowledgements: Red Hat would like to thank Sebastian Krahmer of the SuSE Security Team for reporting this issue.
Affected Software | Affected Version | How to fix |
---|---|---|
Hewlett-Packard HPLIP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-662740 is critical due to the potential for crashing the hplip tool and executing arbitrary code.
To fix REDHAT-BUG-662740, update to the latest version of hplip provided by HP that addresses this vulnerability.
The potential consequences of REDHAT-BUG-662740 include crashing the hplip tool or executing arbitrary code with elevated privileges.
The software affected by REDHAT-BUG-662740 is HP's hplip.
The vulnerability REDHAT-BUG-662740 was reported by Sebastian Krahmer.