FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-2940

This CVE name corresponds to:

Entered Topic
2008-11-29 hplip -- hpssd Denial of Service

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-2940
Phase Assigned(20080630)

Description

The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message.

References

Source Reference
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=455235
MANDRIVA MDVSA-2008:169
REDHAT RHSA-2008:0818
SUSE SUSE-SR:2008:021
UBUNTU USN-674-1
UBUNTU USN-674-2
BID 30683
OVAL oval:org.mitre.oval:def:10136
SECTRACK 1020684
SECUNIA 31470
SECUNIA 31499
SECUNIA 32316
SECUNIA 32792
XF hplip-alertmailing-privilege-escalation(44441)