CVE-2013-6427

Currently unrated

Key Information:

Vendor
HP
Vendor
CVE Published:
9 December 2013

Summary

upgrade.py in the hp-upgrade service in HP Linux Imaging and Printing (HPLIP) 3.x through 3.13.11 launches a program from an http URL, which allows man-in-the-middle attackers to execute arbitrary code by gaining control over the client-server data stream.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.