HP-Plugin Remote Code Execution Vulnerability (CVE-2015-0839)
HP-Plugin Remote Code Execution Vulnerability (CVE-2015-0839)
Release date:
Updated on:
Affected Systems:
HP-Plugin
Description:
Bugtraq id: 74913
CVE (CAN) ID: CVE-2015-0839
This is HP Linux graphics and printing software.
The HP-Plugin utility uses a short key ID to verify and download the binary driver. This allows man-in-the-middle attackers to generate a key with a predictable short ID and induce users to download malicious binary files, execute any code in the context of the affected application.
<* Source: Enrico Zini
*>
Suggestion:
Vendor patch:
HP
--
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://hplipopensource.com/hplip-web/index.html
This article permanently updates the link address: