Oval Definition:oval:com.redhat.rhsa:def:20130133
Revision Date:2013-01-08Version:635
Title:RHSA-2013:0133: hplip3 security and bug fix update (Low)
Description:Hewlett-Packard Linux Imaging and Printing (HPLIP) provides drivers for Hewlett-Packard (HP) printers and multifunction peripherals.

  • It was found that the HP CUPS (Common UNIX Printing System) fax filter in HPLIP created a temporary file in an insecure way. A local attacker could use this flaw to perform a symbolic link attack, overwriting arbitrary files accessible to a process using the fax filter (such as the hp3-sendfax tool). (CVE-2011-2722)

    This update also fixes the following bug:

  • Previous modifications of the hplip3 package to allow it to be installed alongside the original hplip package introduced several problems to fax support; for example, the hp-sendfax utility could become unresponsive. These problems have been fixed with this update. (BZ#501834)

    All users of hplip3 are advised to upgrade to these updated packages, which contain backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2011-2722
    RHSA-2013:0133
    RHSA-2013:0133-00
    RHSA-2013:0133-01
    RHSA-2013:0133-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • hpijs3 is earlier than 1:3.9.8-15.el5
  • AND hpijs3 is signed with Red Hat redhatrelease2 key
  • hplip3 is earlier than 0:3.9.8-15.el5
  • AND hplip3 is signed with Red Hat redhatrelease2 key
  • hplip3-common is earlier than 0:3.9.8-15.el5
  • AND hplip3-common is signed with Red Hat redhatrelease2 key
  • hplip3-gui is earlier than 0:3.9.8-15.el5
  • AND hplip3-gui is signed with Red Hat redhatrelease2 key
  • hplip3-libs is earlier than 0:3.9.8-15.el5
  • AND hplip3-libs is signed with Red Hat redhatrelease2 key
  • libsane-hpaio3 is earlier than 0:3.9.8-15.el5
  • AND libsane-hpaio3 is signed with Red Hat redhatrelease2 key
  • BACK