English | Deutsch | Español | Português
 UserID:
 Passwd:
new user
 About:   Dedicated  | Advanced  | Standard  | Recurring  | No Risk  | Desktop  | Basic  | Single  | Security Seal  | FAQ
  Price/Feature Summary  | Order  | New Vulnerabilities  | Confidentiality  | Vulnerability Search
 Vulnerability   
Search   
    Search 76783 CVE descriptions
and 40246 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.61956
Category:FreeBSD Local Security Checks
Title:FreeBSD Ports: hplip
Summary:FreeBSD Ports: hplip
Description:The remote host is missing an update to the system
as announced in the referenced advisory.

The following package is affected: hplip

CVE-2008-2940
The alert-mailing implementation in HP Linux Imaging and Printing
(HPLIP) 1.6.7 allows local users to gain privileges and send e-mail
messages from the root account via vectors related to the setalerts
message, and lack of validation of the device URI associated with an
event message.

CVE-2008-2941
The hpssd message parser in hpssd.py in HP Linux Imaging and Printing
(HPLIP) 1.6.7 allows local users to cause a denial of service (process
stop) via a crafted packet, as demonstrated by sending 'msg=0' to TCP
port 2207.

Solution:
Update your system with the appropriate patches or
software upgrades.

https://rhn.redhat.com/errata/RHSA-2008-0818.html
http://secunia.com/advisories/31470
http://www.vuxml.org/freebsd/37940643-be1b-11dd-a578-0030843d3802.html
Cross-Ref: BugTraq ID: 30683
Common Vulnerability Exposure (CVE) ID: CVE-2008-2940
http://www.mandriva.com/security/advisories?name=MDVSA-2008:169
http://www.redhat.com/support/errata/RHSA-2008-0818.html
SuSE Security Announcement: SUSE-SR:2008:021 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00006.html
http://www.ubuntu.com/usn/USN-674-1
http://www.ubuntu.com/usn/USN-674-2
http://www.securityfocus.com/bid/30683
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10136
http://securitytracker.com/id?1020684
http://secunia.com/advisories/31470
http://secunia.com/advisories/31499
http://secunia.com/advisories/32316
http://secunia.com/advisories/32792
XForce ISS Database: hplip-alertmailing-privilege-escalation(44441)
http://xforce.iss.net/xforce/xfdb/44441
Common Vulnerability Exposure (CVE) ID: CVE-2008-2941
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10636
http://securitytracker.com/id?1020683
XForce ISS Database: hplip-hpssd-dos(44440)
http://xforce.iss.net/xforce/xfdb/44440
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

This is only one of 40246 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

New User Registration
Email:
UserID:
Passwd:
Please email me your monthly newsletters, informing the latest services, improvements & surveys.
Please email me a vulnerability test announcement whenever a new test is added.
   Privacy
Registered User Login
 
UserID:   
Passwd:  

 Forgot userid or passwd?
Email/Userid:




Home | About Us | Contact Us | Partner Programs | Developer APIs | Privacy | Mailing Lists | Abuse
Security Audits | Managed DNS | Network Monitoring | Site Analyzer | Internet Research Reports
Web Probe | Whois

© 1998-2014 E-Soft Inc. All rights reserved.