7.2
CVSSv2

CVE-2008-2940

Published: 14/08/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message.

Vulnerable Product Search on Vulmon Subscribe to Product

hp linux imaging and printing project 1.6.7

Vendor Advisories

Debian Bug report logs - #499842 CVE-2008-2940/-2941: security issues in hplip Package: hplip; Maintainer for hplip is Debian Printing Team <debian-printing@listsdebianorg>; Source for hplip is src:hplip (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Mon, 22 Sep 2008 22:12:02 UTC Severity ...
USN-674-1 provided packages to fix vulnerabilities in HPLIP Due to an internal archive problem, the updates for Ubuntu 710 would not install properly This update provides fixed packages for Ubuntu 710 ...
It was discovered that the hpssd tool of hplip did not validate privileges in the alert-mailing function A local attacker could exploit this to gain privileges and send e-mail messages from the account of the hplip user This update alters hplip behaviour by preventing users from setting alerts and by moving alert configuration to a root-controlle ...