LWN.net Logo

hplip: insecure temp files

Package(s):hplip CVE #(s):CVE-2013-0200
Created:February 21, 2013 Updated:February 28, 2013
Description: From the Red Hat advisory:

Tim Waugh of Red Hat discovered temporary file handling flaws in HPLIP. A local attacker could use these flaws to perform a symbolic link attack, overwriting arbitrary files accessible to a process using HPLIP.

Alerts:
Red Hat RHSA-2013:0500-02 2013-02-21
Mageia MGASA-2013-0072 2013-02-27
Oracle ELSA-2013-0500 2013-02-28
Scientific Linux SL-hpli-20130304 2013-03-04
CentOS CESA-2013:0500 2013-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds