CVE Vulnerabilities

CVE-2008-2940

Published: Aug 14, 2008 | Modified: Sep 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message.

Affected Software

Name Vendor Start Version End Version
Linux_imaging_and_printing_project Hp 1.6.7 (including) 1.6.7 (including)
Red Hat Enterprise Linux 5 RedHat hplip-0:1.6.7-4.1.el5_2.4 *
Hplip Ubuntu dapper *
Hplip Ubuntu feisty *
Hplip Ubuntu gutsy *
Hplip Ubuntu hardy *

References