4.9
CVSSv2

CVE-2008-2941

Published: 14/08/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The hpssd message parser in hpssd.py in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to cause a denial of service (process stop) via a crafted packet, as demonstrated by sending "msg=0" to TCP port 2207.

Vulnerable Product Search on Vulmon Subscribe to Product

hp linux imaging and printing project 1.6.7

Vendor Advisories

Debian Bug report logs - #499842 CVE-2008-2940/-2941: security issues in hplip Package: hplip; Maintainer for hplip is Debian Printing Team <debian-printing@listsdebianorg>; Source for hplip is src:hplip (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Mon, 22 Sep 2008 22:12:02 UTC Severity ...
USN-674-1 provided packages to fix vulnerabilities in HPLIP Due to an internal archive problem, the updates for Ubuntu 710 would not install properly This update provides fixed packages for Ubuntu 710 ...
It was discovered that the hpssd tool of hplip did not validate privileges in the alert-mailing function A local attacker could exploit this to gain privileges and send e-mail messages from the account of the hplip user This update alters hplip behaviour by preventing users from setting alerts and by moving alert configuration to a root-controlle ...