|
|
Subscribe / Log in / New account

Mageia alert MGASA-2014-0033 (hplip)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2014-0033: Updated hplip package fixes security vulnerabilities
Date:  Wed, 5 Feb 2014 16:27:51 +0100
Message-ID:  <20140205152751.7A06F48724@valstar.mageia.org>

MGASA-2014-0033 - Updated hplip package fixes security vulnerabilities Publication date: 05 Feb 2014 URL: http://advisories.mageia.org/MGASA-2014-0033.html Type: security Affected Mageia releases: 3 Description: It was discovered that the HPLIP Polkit daemon incorrectly handled temporary files. A local attacker could possibly use this issue to overwrite arbitrary files. (CVE-2013-6402) It was discovered that HPLIP contained an upgrade tool that would download code in an unsafe fashion. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to execute arbitrary code. (CVE-2013-6427) Additionnally, this update should fix issues regarding wireless connection to printer hplip after 3.12.9 and prior to version 3.12.11 had issues with setting up wireless connection to printers due to internal code changes which had not been applied consistently. References: - https://bugs.mageia.org/show_bug.cgi?id=11809 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6402 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6427 - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725876 - https://bugs.launchpad.net/hplip/+bug/1048754 SRPMS: - 3/core/hplip-3.12.9-6.3.mga3


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds