Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-0200
HistoryMar 06, 2013 - 12:00 a.m.

CVE-2013-0200

2013-03-0600:00:00
ubuntu.com
ubuntu.com
6

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:N/I:P/A:N

0.0004 Low

EPSS

Percentile

5.1%

HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to
overwrite arbitrary files via a symlink attack on the (1)
/tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3)
/tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out
temporary file, a different vulnerability than CVE-2011-2722.

Bugs

Notes

Author Note
mdeslaur possibly related bugs: https://bugzilla.redhat.com/show_bug.cgi?id=830630 https://bugs.launchpad.net/hplip/+bug/1016507
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchhplip< 3.10.2-2ubuntu2.4UNKNOWN
ubuntu12.04noarchhplip< 3.12.2-1ubuntu3.3UNKNOWN
ubuntu12.10noarchhplip< 3.12.6-3ubuntu4.2UNKNOWN

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:N/I:P/A:N

0.0004 Low

EPSS

Percentile

5.1%