The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message.
References
Configurations
Information
Published : 2008-08-14 13:41
Updated : 2017-09-28 18:31
NVD link : CVE-2008-2940
Mitre link : CVE-2008-2940
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
hp
- linux_imaging_and_printing_project