LWN.net Logo

hplip: multiple vulnerabilties

Package(s):hplip CVE #(s):CVE-2008-2940 CVE-2008-2941
Created:August 13, 2008 Updated:November 24, 2008
Description:

From the Red Hat advisory:

A flaw was discovered in the hplip alert-mailing functionality. A local attacker could elevate their privileges by using specially-crafted packets to trigger alert mails, which are sent by the root account. (CVE-2008-2940)

A flaw was discovered in the hpssd message parser. By sending specially-crafted packets, a local attacker could cause a denial of service, stopping the hpssd process. (CVE-2008-2941)

Alerts:
Mandriva MDVSA-2008:169 2007-08-13
Red Hat RHSA-2008:0818-02 2008-08-12
SuSE SUSE-SR:2008:021 2008-10-17
Ubuntu USN-674-1 2008-11-19
Ubuntu USN-674-2 2008-11-24

(Log in to post comments)

Copyright © 2009, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds