Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.59035
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDKSA-2007:201 (hplip)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to hplip
announced via advisory MDKSA-2007:201.

A vulnerability in the hpssd tool was discovered where it did not
correctly handle shell meta-characters. A local attacker could use
this flaw to execute arbitrary commands as the hplip user.

As well, this update fixes a problem with some HP scanners on Mandriva
Linux 2007.1, particularly HP PSC 1315, which wouldn't be detected
and also fixes a problem with HP 1220 and possibly other models when
scanning via the OpenOffice.org suite.

Updated packages have been patched to prevent these issues.

Affected: 2007.0, 2007.1, 2008.0, Corporate 4.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2007:201
http://qa.mandriva.com/show_bug.cgi?id=28669
http://qa.mandriva.com/show_bug.cgi?id=30719

Risk factor : High

CVSS Score:
7.6

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2007-5208
BugTraq ID: 26054
http://www.securityfocus.com/bid/26054
Debian Security Information: DSA-1462 (Google Search)
http://www.debian.org/security/2008/dsa-1462
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00200.html
http://security.gentoo.org/glsa/glsa-200710-26.xml
http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:201
https://launchpad.net/bugs/149121
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10692
http://www.redhat.com/support/errata/RHSA-2007-0960.html
http://www.securitytracker.com/id?1018806
http://secunia.com/advisories/27202
http://secunia.com/advisories/27221
http://secunia.com/advisories/27224
http://secunia.com/advisories/27232
http://secunia.com/advisories/27271
http://secunia.com/advisories/27332
http://secunia.com/advisories/27397
http://secunia.com/advisories/28453
SuSE Security Announcement: SUSE-SR:2007:021 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2007-10/msg00006.html
https://usn.ubuntu.com/530-1/
http://www.vupen.com/english/advisories/2007/3479
XForce ISS Database: hplip-hpssd-command-execution(37183)
https://exchange.xforce.ibmcloud.com/vulnerabilities/37183
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.