hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a from address, which is not properly handled when invoking sendmail.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade hplip | Jul 30, 2024 | Oct 13, 2007 |
| Gentoo Linux | — | Upgrade net-print/hplip. | Oct 30, 2017 | Oct 12, 2007 |
| Oracle_linux | — | Upgrade hpijsUpgrade libsane-hpaioUpgrade hplip | Oct 16, 2024 | Oct 13, 2007 |
| Suse | — | Upgrade suse-releaseUpgrade hplip-hpijsUpgrade hplip | Feb 17, 2015 | Oct 12, 2007 |
| Ubuntu | — | Upgrade hplip | Nov 8, 2024 | Oct 13, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub