ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signatures for new services, which allows local users to load unauthorized Chai services.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Link | Tags |
---|---|
http://www.phenoelit.de/stuff/HP_Chai.txt | broken link vendor advisory |
http://www.securityfocus.com/bid/5334 | vdb entry third party advisory broken link |
http://online.securityfocus.com/advisories/4317 | patch vendor advisory vdb entry third party advisory broken link |
http://www.iss.net/security_center/static/9695.php | vdb entry broken link |
http://www.securityfocus.com/archive/1/284648 | mailing list vdb entry third party advisory broken link |