HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.
CVSS Details
- CVSS 3.1 Base Score: 3.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade hplip-guiUpgrade hplip-libsUpgrade hplipUpgrade libsane-hpaioUpgrade hplip-commonUpgrade hpijs | Dec 1, 2016 | Mar 6, 2013 |
| Debian | — | Upgrade hplip | Jul 30, 2024 | Mar 6, 2013 |
| Oracle Solaris | — | Upgrade print/filter/hplip to version 3.10.9-0.175.1.19.0.3.0 on Solaris 11.1 | May 29, 2017 | Mar 6, 2013 |
| Oracle_linux | — | Upgrade hplipUpgrade libsane-hpaioUpgrade hpijsUpgrade hplip-commonUpgrade hplip-guiUpgrade hplip-libs | Oct 16, 2024 | Mar 6, 2013 |
| Suse | — | Upgrade hplipUpgrade hplip-hpijs | Feb 5, 2014 | Mar 6, 2013 |
| Ubuntu | — | Upgrade hplip | Nov 8, 2024 | Mar 6, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub