The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/44441 | vdb entry |
http://www.securityfocus.com/bid/30683 | vdb entry |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10136 | vdb entry signature |
http://secunia.com/advisories/31470 | third party advisory |
http://www.mandriva.com/security/advisories?name=MDVSA-2008:169 | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00006.html | vendor advisory |
http://www.ubuntu.com/usn/USN-674-1 | vendor advisory |
http://www.ubuntu.com/usn/USN-674-2 | vendor advisory |
http://securitytracker.com/id?1020684 | vdb entry |
http://secunia.com/advisories/32792 | third party advisory |
http://secunia.com/advisories/31499 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=455235 | |
http://secunia.com/advisories/32316 | third party advisory |
http://www.redhat.com/support/errata/RHSA-2008-0818.html | vendor advisory |