Remote Code Execution in HP Linux Imaging and Printing by HP
CVE-2013-6427

Currently unrated

Key Information:

Vendor
HP
Vendor
CVE Published:
9 December 2013

Summary

The hp-upgrade service in HP Linux Imaging and Printing (HPLIP) versions 3.x through 3.13.11 is vulnerable to a security flaw where an attacker can exploit the upgrade.py script to execute arbitrary code. By leveraging a man-in-the-middle attack, an attacker can intercept client-server communications and launch malicious programs from an HTTP URL, compromising the client's system security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.