The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux_imaging_and_printing_project | Hp | 1.6.7 (including) | 1.6.7 (including) |
Red Hat Enterprise Linux 5 | RedHat | hplip-0:1.6.7-4.1.el5_2.4 | * |
Hplip | Ubuntu | dapper | * |
Hplip | Ubuntu | feisty | * |
Hplip | Ubuntu | gutsy | * |
Hplip | Ubuntu | hardy | * |