Remote Code Execution in HP Linux Imaging and Printing by HP
CVE-2013-6427
Currently unrated
Key Information:
- Vendor
- HP
- Vendor
- CVE Published:
- 9 December 2013
Summary
The hp-upgrade service in HP Linux Imaging and Printing (HPLIP) versions 3.x through 3.13.11 is vulnerable to a security flaw where an attacker can exploit the upgrade.py script to execute arbitrary code. By leveraging a man-in-the-middle attack, an attacker can intercept client-server communications and launch malicious programs from an HTTP URL, compromising the client's system security.
References
Timeline
Vulnerability published
Vulnerability Reserved