Stack-based buffer overflow in the hpmud_get_pml function in io/hpmud/pml.c in Hewlett-Packard Linux Imaging and Printing (HPLIP) 1.6.7, 3.9.8, 3.10.9, and probably other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SNMP response with a large length value.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade hplip3-guiUpgrade hplipUpgrade hpijs3Upgrade hplip3-commonUpgrade hplip3-libsUpgrade libsane-hpaio3Upgrade hpijsUpgrade hplip3Upgrade libsane-hpaio | Dec 1, 2016 | Jan 20, 2011 |
| Debian | — | Upgrade hplip | Jul 30, 2024 | Jan 20, 2011 |
| Gentoo Linux | — | Upgrade net-print/hplip. | Oct 30, 2017 | Jan 20, 2011 |
| Oracle_linux | — | Upgrade hplip3Upgrade hplip3-guiUpgrade hplip-commonUpgrade hplip3-libsUpgrade libsane-hpaio3Upgrade hpijsUpgrade hplip-libsUpgrade hplip3-commonUpgrade hpijs3Upgrade hplipUpgrade libsane-hpaioUpgrade hplip-gui | Oct 16, 2024 | Jan 20, 2011 |
| Suse | — | Upgrade hplip-hpijsUpgrade hplip-develUpgrade hplip-saneUpgrade hplip | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade hplip | Nov 8, 2024 | Jan 20, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub