Описание
ELSA-2013-0500: hplip security, bug fix and enhancement update (LOW)
[3.12.4-4]
- Applied patch to fix CVE-2013-0200, temporary file vulnerability (bug #902163).
- Fixed hpijs-marker-supply patch.
[3.12.4-3]
- Make 'hp-check' check for hpaio set-up correctly (bug #683007).
[3.12.4-2]
- Added more fixes from Fedora (bug #731900).
[3.12.4-1]
- Re-based to 3.12.4 with fixes from Fedora (bug #731900). No longer need no-system-tray, openPPD, addgroup, emit-SIGNAL, fab-root-crash, newline, hpaio-segfault, dbus-threads, or cups-web patches.
[3.10.9-4]
- The hpijs sub-package no longer requires cupsddk-drivers (which no longer exists as a real package), but cups >= 1.4 (bug #829453).
Обновленные пакеты
Oracle Linux 6
Oracle Linux x86_64
hpijs
3.12.4-4.el6
hplip
3.12.4-4.el6
hplip-common
3.12.4-4.el6
hplip-gui
3.12.4-4.el6
hplip-libs
3.12.4-4.el6
libsane-hpaio
3.12.4-4.el6
Oracle Linux i686
hpijs
3.12.4-4.el6
hplip
3.12.4-4.el6
hplip-common
3.12.4-4.el6
hplip-gui
3.12.4-4.el6
hplip-libs
3.12.4-4.el6
libsane-hpaio
3.12.4-4.el6
Связанные CVE
Связанные уязвимости
HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.
HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.
HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.
HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local user ...
The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out temporary file.