CVE-2008-2940/-2941: security issues in hplip

Related Vulnerabilities: CVE-2008-2940   CVE-2008-2941  

Debian Bug report logs - #499842
CVE-2008-2940/-2941: security issues in hplip

version graph

Reported by: Stefan Fritsch <sf@sfritsch.de>

Date: Mon, 22 Sep 2008 22:12:02 UTC

Severity: important

Tags: fixed-upstream, security

Found in version hplip/1.6.10-3

Fixed in version hplip/2.8.6-1

Done: Mark Purcell <msp@debian.org>

Bug is archived. No further changes may be made.

Forwarded to https://bugs.launchpad.net/hplip/+bug/273370

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian HPIJS and HPLIP maintainers <pkg-hpijs-devel@lists.alioth.debian.org>:
Bug#499842; Package hplip. (Mon, 22 Sep 2008 22:12:05 GMT) (full text, mbox, link).


Acknowledgement sent to Stefan Fritsch <sf@sfritsch.de>:
New Bug report received and forwarded. Copy sent to Debian HPIJS and HPLIP maintainers <pkg-hpijs-devel@lists.alioth.debian.org>. (Mon, 22 Sep 2008 22:12:05 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Stefan Fritsch <sf@sfritsch.de>
To: submit@bugs.debian.org
Subject: CVE-2008-2940/-2941: security issues in hplip
Date: Tue, 23 Sep 2008 00:11:27 +0200
Package: hplip
Version: 1.6.10-3
Severity: important
Tags: security

Hi,
the following CVE (Common Vulnerabilities & Exposures) ids were
published for hplip.

CVE-2008-2940[0]:
| The alert-mailing implementation in HP Linux Imaging and Printing
| (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail
| messages from the root account via vectors related to the setalerts
| message, and lack of validation of the device URI associated with an
| event message.

CVE-2008-2941[1]:
| The hpssd message parser in hpssd.py in HP Linux Imaging and
| Printing (HPLIP) 1.6.7 allows local users to cause a denial of
| service (process stop) via a crafted packet, as demonstrated by
| sending "msg=0" to TCP port 2207.

If you fix the vulnerabilities please also make sure to include the
CVE ids in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2940
    http://security-tracker.debian.net/tracker/CVE-2008-2940
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2941
    http://security-tracker.debian.net/tracker/CVE-2008-2941




Information forwarded to debian-bugs-dist@lists.debian.org, Debian HPIJS and HPLIP maintainers <pkg-hpijs-devel@lists.alioth.debian.org>:
Bug#499842; Package hplip. (Fri, 03 Oct 2008 18:48:12 GMT) (full text, mbox, link).


Acknowledgement sent to Stefan Fritsch <sf@sfritsch.de>:
Extra info received and forwarded to list. Copy sent to Debian HPIJS and HPLIP maintainers <pkg-hpijs-devel@lists.alioth.debian.org>. (Fri, 03 Oct 2008 18:48:12 GMT) (full text, mbox, link).


Message #10 received at 499842@bugs.debian.org (full text, mbox, reply):

From: Stefan Fritsch <sf@sfritsch.de>
To: 499842@bugs.debian.org
Cc: control@bugs.debian.org
Subject: CVE-2008-2940/-2941: security issues in hplip
Date: Fri, 3 Oct 2008 20:40:29 +0200
fixed 499842 2.8.6-1
thanks

Both issues affect 1.6.10-3etch4 in etch.

Of the three patches, this one

https://bugzilla.redhat.com/attachment.cgi?id=312880

introduces a new config file /etc/hp/alerts.conf . I am not sure if 
this is good for a stable security update, but it may be ok if the 
feature is nearly never used. Maybe the maintainer could comment?


The code in lenny (2.8.6) is quite different. AFAICS, hpssd does not 
open any listening socket anymore so CVE-2008-2941 is not an issue. 
And the alert email code seems to be commented out, therefore 
CVE-2008-2940 is also an non-issue.




Bug marked as fixed in version 2.8.6-1. Request was from Stefan Fritsch <sf@sfritsch.de> to control@bugs.debian.org. (Fri, 03 Oct 2008 18:48:13 GMT) (full text, mbox, link).


Noted your statement that Bug has been forwarded to https://bugs.launchpad.net/hplip/+bug/273370. Request was from Mark Purcell <msp@debian.org> to control@bugs.debian.org. (Fri, 03 Oct 2008 23:57:02 GMT) (full text, mbox, link).


Message sent on to Stefan Fritsch <sf@sfritsch.de>:
Bug#499842. (Fri, 03 Oct 2008 23:57:04 GMT) (full text, mbox, link).


Message #17 received at 499842-submitter@bugs.debian.org (full text, mbox, reply):

From: Mark Purcell <msp@debian.org>
To: control@bugs.debian.org
Cc: 499842-submitter@bugs.debian.org
Subject: bug 499842 is forwarded to https://bugs.launchpad.net/hplip/+bug/273370
Date: Sat, 04 Oct 2008 09:53:40 +1000
forwarded 499842 https://bugs.launchpad.net/hplip/+bug/273370





Forwarded-to-address changed from https://bugs.launchpad.net/hplip/+bug/273370 to https://bugs.launchpad.net/hplip/+bug/273370, merged-upstream: https://bugs.launchpad.net/bugs/273370. Request was from bts-link-upstream@lists.alioth.debian.org to control@bugs.debian.org. (Fri, 16 Jan 2009 20:56:23 GMT) (full text, mbox, link).


Forwarded-to-address changed from https://bugs.launchpad.net/hplip/+bug/273370, merged-upstream: https://bugs.launchpad.net/bugs/273370 to https://bugs.launchpad.net/hplip/+bug/273370, merged-upstream: https://bugs.launchpad.net/bugs/273370. Request was from bts-link-upstream@lists.alioth.debian.org to control@bugs.debian.org. (Wed, 21 Jan 2009 21:39:49 GMT) (full text, mbox, link).


Forwarded-to-address changed from https://bugs.launchpad.net/hplip/+bug/273370, merged-upstream: https://bugs.launchpad.net/bugs/273370 to https://bugs.launchpad.net/hplip/+bug/273370, merged-upstream: https://bugs.launchpad.net/bugs/273370. Request was from bts-link-upstream@lists.alioth.debian.org to control@bugs.debian.org. (Sun, 01 Feb 2009 22:15:57 GMT) (full text, mbox, link).


Forwarded-to-address changed from https://bugs.launchpad.net/hplip/+bug/273370, merged-upstream: https://bugs.launchpad.net/bugs/273370 to https://bugs.launchpad.net/hplip/+bug/273370, merged-upstream: https://bugs.launchpad.net/bugs/273370. Request was from bts-link-upstream@lists.alioth.debian.org to control@bugs.debian.org. (Thu, 05 Feb 2009 19:16:39 GMT) (full text, mbox, link).


Forwarded-to-address changed from https://bugs.launchpad.net/hplip/+bug/273370, merged-upstream: https://bugs.launchpad.net/bugs/273370 to https://bugs.launchpad.net/hplip/+bug/273370, merged-upstream: https://bugs.launchpad.net/bugs/273370. Request was from bts-link-upstream@lists.alioth.debian.org to control@bugs.debian.org. (Tue, 10 Feb 2009 18:33:48 GMT) (full text, mbox, link).


Forwarded-to-address changed from https://bugs.launchpad.net/hplip/+bug/273370, merged-upstream: https://bugs.launchpad.net/bugs/273370 to https://bugs.launchpad.net/hplip/+bug/273370. Request was from bts-link-upstream@lists.alioth.debian.org to control@bugs.debian.org. (Sun, 15 Feb 2009 21:52:47 GMT) (full text, mbox, link).


Tags added: fixed-upstream Request was from bts-link-upstream@lists.alioth.debian.org to control@bugs.debian.org. (Wed, 27 May 2009 21:27:31 GMT) (full text, mbox, link).


Reply sent to Mark Purcell <msp@debian.org>:
You have taken responsibility. (Fri, 21 May 2010 07:51:08 GMT) (full text, mbox, link).


Notification sent to Stefan Fritsch <sf@sfritsch.de>:
Bug acknowledged by developer. (Fri, 21 May 2010 07:51:08 GMT) (full text, mbox, link).


Message #36 received at 499842-done@bugs.debian.org (full text, mbox, reply):

From: Mark Purcell <msp@debian.org>
To: 499842-done@bugs.debian.org
Subject: Fwd: Bug#499842: CVE-2008-2940/-2941: security issues in hplip
Date: Fri, 21 May 2010 17:48:14 +1000
[Message part 1 (text/plain, inline)]
Package: hplip
Version: 2.8.6-1

----------  Forwarded Message  ----------

Subject: Bug#499842: CVE-2008-2940/-2941: security issues in hplip
Date: Saturday 04 October 2008, 04:40:29
From: Stefan Fritsch <sf@sfritsch.de>
To: 499842@bugs.debian.org
CC: control@bugs.debian.org

fixed 499842 2.8.6-1
thanks

Both issues affect 1.6.10-3etch4 in etch.

Of the three patches, this one

https://bugzilla.redhat.com/attachment.cgi?id=312880

introduces a new config file /etc/hp/alerts.conf . I am not sure if 
this is good for a stable security update, but it may be ok if the 
feature is nearly never used. Maybe the maintainer could comment?


The code in lenny (2.8.6) is quite different. AFAICS, hpssd does not 
open any listening socket anymore so CVE-2008-2941 is not an issue. 
And the alert email code seems to be commented out, therefore 
CVE-2008-2940 is also an non-issue.





-----------------------------------------
[signature.asc (application/pgp-signature, inline)]

Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sat, 19 Jun 2010 07:33:35 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 16:31:46 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.