Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.870874
Categoría:Red Hat Local Security Checks
Título:RedHat Update for hplip3 RHSA-2013:0133-01
Resumen:The remote host is missing an update for the 'hplip3'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'hplip3'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Hewlett-Packard Linux Imaging and Printing (HPLIP) provides drivers for
Hewlett-Packard (HP) printers and multifunction peripherals.

It was found that the HP CUPS (Common UNIX Printing System) fax filter in
HPLIP created a temporary file in an insecure way. A local attacker could
use this flaw to perform a symbolic link attack, overwriting arbitrary
files accessible to a process using the fax filter (such as the
hp3-sendfax tool). (CVE-2011-2722)

This update also fixes the following bug:

* Previous modifications of the hplip3 package to allow it to be installed
alongside the original hplip package introduced several problems to fax
support. For example, the hp-sendfax utility could become unresponsive.
These problems have been fixed with this update. (BZ#501834)

All users of hplip3 are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.

Affected Software/OS:
hplip3 on Red Hat Enterprise Linux (v. 5 server)

Solution:
Please Install the Updated Packages.

CVSS Score:
1.2

CVSS Vector:
AV:L/AC:H/Au:N/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-2722
48441
http://secunia.com/advisories/48441
55083
http://secunia.com/advisories/55083
GLSA-201203-17
http://security.gentoo.org/glsa/glsa-201203-17.xml
RHSA-2013:0133
http://rhn.redhat.com/errata/RHSA-2013-0133.html
USN-1981-1
http://www.ubuntu.com/usn/USN-1981-1
[oss-security] 20110726 Re: CVE request: hplip: insecure tmp file handling
http://www.openwall.com/lists/oss-security/2011/07/26/14
http://hplipopensource.com/hplip-web/release_notes.html
https://bugs.launchpad.net/hplip/+bug/809904
https://bugzilla.novell.com/show_bug.cgi?id=704608
https://bugzilla.redhat.com/attachment.cgi?id=515866&action=diff
https://bugzilla.redhat.com/show_bug.cgi?id=725830
CopyrightCopyright (C) 2013 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.