USN-7202-1: HPLIP vulnerability
Published Jan 13, 2025
·Updated
Kevin Backhouse discovered that HPLIP incorrectly handled certain MDNS responses. A remote attacker could use this issue to cause HPLIP to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/hplip<3.20.3+dfsg0-2ubuntu0.1
3.20.3+dfsg0-2ubuntu0.1
Ubuntu Ubuntu=20.04
Event History
Jan 13, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7202-1?
USN-7202-1 is classified as a critical vulnerability due to its potential to cause a denial of service and enable arbitrary code execution.
2
How do I fix USN-7202-1?
To fix USN-7202-1, update the HPLIP package to version 3.20.3+dfsg0-2ubuntu0.1 or later.
3
What software is affected by USN-7202-1?
USN-7202-1 affects HPLIP version 3.20.3+dfsg0-2ubuntu0.1 on Ubuntu 20.04.
4
Can USN-7202-1 be exploited remotely?
Yes, USN-7202-1 can be exploited remotely by an attacker through malicious MDNS responses.
5
What are the consequences of USN-7202-1?
The consequences of USN-7202-1 include possible service crashes and unauthorized code execution.