Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.58960
Categoría:Red Hat Local Security Checks
Título:RedHat Security Advisory RHSA-2007:0960
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing updates announced in
advisory RHSA-2007:0960.

The hplip (Hewlett-Packard Linux Imaging and Printing Project) package
provides drivers for HP printers and multi-function peripherals.

Kees Cook discovered a flaw in the way the hplip hpssd daemon handled user
input. A local attacker could send a specially crafted request to the hpssd
daemon, possibly allowing them to run arbitrary commands as the root user.
(CVE-2007-5208). On Red Hat Enterprise Linux 5, the SELinux targeted
policy for hpssd which is enabled by default, blocks the ability to exploit
this issue to run arbitrary code.

Users of hplip are advised to upgrade to this updated package, which
contains backported patches to resolve this issue.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2007-0960.html
http://www.redhat.com/security/updates/classification/#important

Risk factor : High

CVSS Score:
7.6

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2007-5208
BugTraq ID: 26054
http://www.securityfocus.com/bid/26054
Debian Security Information: DSA-1462 (Google Search)
http://www.debian.org/security/2008/dsa-1462
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00200.html
http://security.gentoo.org/glsa/glsa-200710-26.xml
http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:201
https://launchpad.net/bugs/149121
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10692
http://www.redhat.com/support/errata/RHSA-2007-0960.html
http://www.securitytracker.com/id?1018806
http://secunia.com/advisories/27202
http://secunia.com/advisories/27221
http://secunia.com/advisories/27224
http://secunia.com/advisories/27232
http://secunia.com/advisories/27271
http://secunia.com/advisories/27332
http://secunia.com/advisories/27397
http://secunia.com/advisories/28453
SuSE Security Announcement: SUSE-SR:2007:021 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2007-10/msg00006.html
https://usn.ubuntu.com/530-1/
http://www.vupen.com/english/advisories/2007/3479
XForce ISS Database: hplip-hpssd-command-execution(37183)
https://exchange.xforce.ibmcloud.com/vulnerabilities/37183
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.