REDHAT-BUG-662740: Medium severity hplip (hp linux imaging and printing) vulnerability
Sebastian Krahmer reported a flaw in how hplip discovered SNMP devices. If certain hplip commands were run that queried SNMP devices, and a malicious user were able to send crafted SNMP responses, it could cause the running hplip tool to crash or, possibly, execute arbitrary code with the privileges of the user running the tool.
Acknowledgements:
Red Hat would like to thank Sebastian Krahmer of the SuSE Security Team for reporting this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-662740?
The severity of REDHAT-BUG-662740 is critical due to the potential for crashing the hplip tool and executing arbitrary code.
How do I fix REDHAT-BUG-662740?
To fix REDHAT-BUG-662740, update to the latest version of hplip provided by HP that addresses this vulnerability.
What are the potential consequences of REDHAT-BUG-662740?
The potential consequences of REDHAT-BUG-662740 include crashing the hplip tool or executing arbitrary code with elevated privileges.
Which software is affected by REDHAT-BUG-662740?
The software affected by REDHAT-BUG-662740 is HP's hplip.
Who reported the vulnerability REDHAT-BUG-662740?
The vulnerability REDHAT-BUG-662740 was reported by Sebastian Krahmer.