Vulnerability Name: | CVE-2008-2941 (CCN-44440) | ||||||||||||||||||||||||||||||||
Assigned: | 2008-08-12 | ||||||||||||||||||||||||||||||||
Published: | 2008-08-12 | ||||||||||||||||||||||||||||||||
Updated: | 2017-09-29 | ||||||||||||||||||||||||||||||||
Summary: | The hpssd message parser in hpssd.py in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to cause a denial of service (process stop) via a crafted packet, as demonstrated by sending "msg=0" to TCP port 2207. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C) 3.7 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2008-2941 Source: CCN Type: HPLIP Web page HP Linux Imaging and Printing (HPLIP) Source: SUSE Type: UNKNOWN SUSE-SR:2008:021 Source: CCN Type: RHSA-2008-0818 Moderate: hplip security update Source: CCN Type: SA31470 HPLIP hpssd Denial of Service Source: SECUNIA Type: UNKNOWN 31470 Source: SECUNIA Type: UNKNOWN 31499 Source: SECUNIA Type: UNKNOWN 32316 Source: SECUNIA Type: UNKNOWN 32792 Source: CCN Type: SECTRACK ID: 1020683 HP Linux Imaging and Printing Project (hplip) Bug in hpssd Message Parser Lets Local Users Deny Service Source: SECTRACK Type: UNKNOWN 1020683 Source: MANDRIVA Type: UNKNOWN MDVSA-2008:169 Source: REDHAT Type: UNKNOWN RHSA-2008:0818 Source: BID Type: UNKNOWN 30683 Source: CCN Type: BID-30683 HP Linux Imaging and Printing System Privilege Escalation And Denial Of Service Vulnerabilities Source: CCN Type: USN-674-1 HPLIP vulnerabilities Source: UBUNTU Type: UNKNOWN USN-674-1 Source: CCN Type: USN-674-2 HPLIP vulnerabilities Source: UBUNTU Type: UNKNOWN USN-674-2 Source: CCN Type: Red Hat Bugzilla Bug 457052 CVE-2008-2941 hplip hpssd.py Denial-Of-Service parsing vulnerability Source: CONFIRM Type: Patch https://bugzilla.redhat.com/show_bug.cgi?id=457052 Source: XF Type: UNKNOWN hplip-hpssd-dos(44440) Source: XF Type: UNKNOWN hplip-hpssd-dos(44440) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10636 Source: SUSE Type: SUSE-SR:2008:021 SUSE Security Summary Report | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |