CVE-2008-2940 hpssd of hplip allows unprivileged user to trigger alert mail

Bug #273370 reported by Mark Purcell
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
HPLIP
Fix Released
Medium
dwelch91
hplip (Debian)
Fix Released
Unknown
hplip (Fedora)
Fix Released
Medium

Bug Description

Request confirmation that these two CVE's (hplip 1.6.7) are fixed in the current hplip and if so which version of hplip were they fixed in.

hpssd was replaced by hp-systray in 2.8.4, but was the code fixed?

CVE-2008-2940
The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message.

CVE-2008-2941
The hpssd message parser in hpssd.py in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to cause a denial of service (process stop) via a crafted packet, as demonstrated by sending "msg=0" to TCP port 2207.

CVE References

Revision history for this message
In , Marc (marc-redhat-bugs-1) wrote :

==Description==

hpssd allows unprivileged local users to trigger alert mails
by sending specially crafted packets

Revision history for this message
In , Tim (tim-redhat-bugs) wrote :

Created attachment 312878
hplip-validate-uri.patch

This is the first of two patches to address this problem. This patch performs
validation on the device URI when handling an 'event' message, and improves the
validation code.

Revision history for this message
In , Tim (tim-redhat-bugs) wrote :

Created attachment 312880
hplip-static-alerts-table.patch

This is the second patch, which implements a static alerts table, stored in
/etc/hp/alerts.conf. The 'setalerts' message now has no effect.

Revision history for this message
In , Josh (josh-redhat-bugs) wrote :

Lifting embargo

Revision history for this message
In , Red (red-redhat-bugs) wrote :

This issue was addressed in:

Red Hat Enterprise Linux:
  http://rhn.redhat.com/errata/RHSA-2008-0818.html

Changed in hplip:
status: Unknown → Fix Released
Changed in hplip:
status: Unknown → New
Changed in hplip:
status: New → Confirmed
Revision history for this message
dwelch91 (dwelch91) wrote :

CVE-2008-2940 (email alerts) - this feature was removed from HPLIP in a previous release. I will have to research the exact version.

CVE-2008-2941 (DOS) - the message passing system over sockets was replaced with DBus in a previous release. I will have to research the exact version.

Changed in hplip:
assignee: nobody → dwelch91
status: New → Triaged
importance: Undecided → Medium
Changed in hplip:
status: Triaged → Fix Released
Changed in hplip (Debian):
status: Confirmed → Fix Released
Changed in hplip (Fedora):
importance: Unknown → Medium
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.