Lucene search

K
cve[email protected]CVE-2011-2722
HistoryMay 25, 2012 - 8:55 p.m.

CVE-2011-2722

2012-05-2520:55:01
CWE-59
web.nvd.nist.gov
31
cve-2011-2722
security
hplip
file overwrite
symlink attack
nvd

1.2 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:H/Au:N/C:N/I:P/A:N

5.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out temporary file.

Affected configurations

NVD
Node
hplinux_imaging_and_printing_projectRange3.11.5
OR
hplinux_imaging_and_printing_projectMatch3.9.2
OR
hplinux_imaging_and_printing_projectMatch3.9.4
OR
hplinux_imaging_and_printing_projectMatch3.9.4b
OR
hplinux_imaging_and_printing_projectMatch3.9.6
OR
hplinux_imaging_and_printing_projectMatch3.9.8
OR
hplinux_imaging_and_printing_projectMatch3.9.10
OR
hplinux_imaging_and_printing_projectMatch3.9.12
OR
hplinux_imaging_and_printing_projectMatch3.10.2
OR
hplinux_imaging_and_printing_projectMatch3.10.5
OR
hplinux_imaging_and_printing_projectMatch3.10.6
OR
hplinux_imaging_and_printing_projectMatch3.10.9
OR
hplinux_imaging_and_printing_projectMatch3.11.1
OR
hplinux_imaging_and_printing_projectMatch3.11.3
OR
hplinux_imaging_and_printing_projectMatch3.11.3a
OR
hplinux_imaging_and_printing_projectMatch3.11.7

1.2 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:H/Au:N/C:N/I:P/A:N

5.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%