Описание
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
A flaw was found in HPLIP (HP Linux Imaging and Printing) software. Multiple vulnerabilities within several components could allow a remote attacker to execute code on the system, gain elevated privileges, or access sensitive information. These issues could also lead to a denial of service, making the system unavailable, or unauthorized changes to files under certain conditions.
Меры по смягчению последствий
To mitigate this vulnerability, if HPLIP functionality is not required, consider removing the hplip package. This action will remove support for HP printers and may impact printing capabilities. Use the system's package manager to perform this operation. For example, on Red Hat Enterprise Linux, execute sudo dnf remove hplip.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | hplip | Fix deferred | ||
| Red Hat Enterprise Linux 6 | hplip | Out of support scope | ||
| Red Hat Enterprise Linux 7 | hplip | Fix deferred | ||
| Red Hat Enterprise Linux 8 | hplip | Fix deferred | ||
| Red Hat Enterprise Linux 9 | hplip | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
4.6 Medium
CVSS3
Связанные уязвимости
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
HP has identified and remediated multiple externally reported vulnerab ...
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
EPSS
4.6 Medium
CVSS3