Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-43023

Опубликовано: 28 июл. 2025
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of a weak code signing key, Digital Signature Algorithm (DSA).

A flaw was found in the HP Linux Imaging and Printing Software (HPLIP). This vulnerability is due to the use of a weak Digital Signature Algorithm (DSA) for code signing. A remote attacker could exploit this weakness to forge signatures, potentially leading to the execution of unauthorized code or tampering with the software. This could compromise the integrity and confidentiality of the affected system.

Отчет

This flaw relates to the method with which HP distributes the their HP imaging and printing software. Users who install this product via Red Hat package management tools are not affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10hplipFix deferred
Red Hat Enterprise Linux 6hplipOut of support scope
Red Hat Enterprise Linux 7hplipOut of support scope
Red Hat Enterprise Linux 8hplipFix deferred
Red Hat Enterprise Linux 9hplipFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2384011hplip: HP Linux Imaging and Printing Software - Use of DSA Key

EPSS

Процентиль: 16%
0.00246
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 1 года назад

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of a weak code signing key, Digital Signature Algorithm (DSA).

CVSS3: 9.1
nvd
около 1 года назад

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of a weak code signing key, Digital Signature Algorithm (DSA).

CVSS3: 9.1
debian
около 1 года назад

A potential security vulnerability has been identified in the HP Linux ...

CVSS3: 9.1
github
около 1 года назад

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of a weak code signing key, Digital Signature Algorithm (DSA).

CVSS3: 5
fstec
около 1 года назад

Уязвимость программного обеспечения HP Linux Imaging and Printing (HPLIP), связанная с ошибками проверки криптографической подписи, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 16%
0.00246
Низкий

5 Medium

CVSS3