CVE Vulnerabilities

CVE-2008-2940

Published: Aug 14, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message.

Affected Software

NameVendorStart VersionEnd Version
Linux_imaging_and_printing_projectHp1.6.7 (including)1.6.7 (including)
Red Hat Enterprise Linux 5RedHathplip-0:1.6.7-4.1.el5_2.4*
HplipUbuntudapper*
HplipUbuntufeisty*
HplipUbuntugutsy*
HplipUbuntuhardy*

References