1.2
CVSSv2

CVE-2011-2722

Published: 25/05/2012 Updated: 13/02/2023
CVSS v2 Base Score: 1.2 | Impact Score: 2.9 | Exploitability Score: 1.9
VMScore: 107
Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x prior to 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

hp linux imaging and printing project 3.9.6

hp linux imaging and printing project 3.10.6

hp linux imaging and printing project 3.11.1

hp linux imaging and printing project 3.11.3a

hp linux imaging and printing project 3.9.4b

hp linux imaging and printing project 3.9.12

hp linux imaging and printing project 3.9.4

hp linux imaging and printing project 3.9.10

hp linux imaging and printing project 3.10.9

hp linux imaging and printing project 3.9.8

hp linux imaging and printing project 3.10.5

hp linux imaging and printing project 3.11.3

hp linux imaging and printing project 3.9.2

hp linux imaging and printing project 3.10.2

hp linux imaging and printing project

hp linux imaging and printing project 3.11.7

Vendor Advisories

Debian Bug report logs - #635549 Two security issues Package: hplip; Maintainer for hplip is Debian Printing Team <debian-printing@listsdebianorg>; Source for hplip is src:hplip (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 26 Jul 2011 21:06:24 UTC Severity: grave Tags: security ...
HPLIP could be made to overwrite files ...
Synopsis Low: hplip security, bug fix and enhancement update Type/Severity Security Advisory: Low Topic Updated hplip packages that fix several security issues, multiple bugs, andadd various enhancements are now available for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this updat ...
Synopsis Low: hplip3 security and bug fix update Type/Severity Security Advisory: Low Topic Updated hplip3 packages that fix one security issue and one bug are nowavailable for Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having lowsecurity impact A Common Vulnerab ...