Vulnerability Name:

CVE-2013-0200 (CCN-82518)

Assigned:2012-12-06
Published:2013-02-21
Updated:2023-02-13
Summary:HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.
CVSS v3 Severity:5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:1.9 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N)
1.8 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
3.3 Low (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
1.9 Low (REDHAT CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N)
1.8 Low (REDHAT Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-377
Vulnerability Consequences:File Manipulation
References:Source: secalert@redhat.com
Type: Patch
secalert@redhat.com

Source: MITRE
Type: CNA
CVE-2013-0200

Source: CCN
Type: HPLIP Web page
HP Linux Imaging and Printing (HPLIP)

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: DEBIAN
Type: DSA-2829
hplip -- several vulnerabilities

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: BID-58079
HP Linux Imaging and Printing CVE-2013-0200 Insecure Temporary File Creation Vulnerability

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: Red Hat Bugzilla Bug 902163
CVE-2013-0200 hplip: insecure temporary file handling flaws

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: XF
Type: UNKNOWN
hp-linux-printing-symlink(82518)

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:hp:hplip:2.8.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20130200
    V
    CVE-2013-0200
    2022-05-20
    oval:org.opensuse.security:def:33111
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:57149
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:33061
    P
    Security update for glib-networking (Important)
    2021-12-13
    oval:org.opensuse.security:def:33060
    P
    Security update for MozillaFirefox (Important)
    2021-12-12
    oval:org.opensuse.security:def:30152
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-11-23
    oval:org.opensuse.security:def:32224
    P
    Security update for postgresql96 (Important)
    2021-11-22
    oval:org.opensuse.security:def:33740
    P
    Security update for samba (Important)
    2021-11-19
    oval:org.opensuse.security:def:33738
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:31700
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:30259
    P
    Security update for postgresql10 (Important)
    2021-10-20
    oval:org.opensuse.security:def:34574
    P
    Security update for fetchmail (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:33980
    P
    Security update for sqlite3 (Important)
    2021-09-23
    oval:org.opensuse.security:def:26123
    P
    Security update for openssl-1_0_0 (Low)
    2021-09-09
    oval:org.opensuse.security:def:34534
    P
    Security update for grilo (Important)
    2021-09-09
    oval:org.opensuse.security:def:30240
    P
    Security update for bind (Moderate)
    2021-08-30
    oval:org.opensuse.security:def:55941
    P
    Security update for unrar (Moderate)
    2021-08-25
    oval:org.opensuse.security:def:29405
    P
    Security update for djvulibre (Important)
    2021-08-05
    oval:org.opensuse.security:def:33683
    P
    Security update for libsolv (Important)
    2021-06-28
    oval:org.opensuse.security:def:30097
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:36148
    P
    hplip-3.11.10-0.6.11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42555
    P
    hplip-3.11.10-0.6.11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:55195
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:30201
    P
    Security update for qemu (Important)
    2021-06-02
    oval:org.opensuse.security:def:55903
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:56022
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:31615
    P
    Security update for cups (Important)
    2021-04-30
    oval:org.opensuse.security:def:55178
    P
    Security update for java-1_7_0-openjdk (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:31614
    P
    Security update for java-1_7_0-openjdk (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:26039
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:33896
    P
    Security update for MozillaFirefox (Important)
    2021-04-27
    oval:org.opensuse.security:def:29348
    P
    Security update for sudo (Important)
    2021-04-20
    oval:org.opensuse.security:def:33891
    P
    Security update for xorg-x11-server (Important)
    2021-04-13
    oval:org.opensuse.security:def:32068
    P
    Security update for spamassassin (Important)
    2021-04-12
    oval:org.opensuse.security:def:33789
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:29490
    P
    Security update for openssl (Moderate)
    2021-03-24
    oval:org.opensuse.security:def:55873
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:32280
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:33072
    P
    Security update for openvswitch (Important)
    2021-02-12
    oval:org.opensuse.security:def:54750
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP2) (Important)
    2021-02-10
    oval:org.opensuse.security:def:31626
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:55829
    P
    Security update for java-1_7_1-ibm (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:27260
    P
    pango on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29714
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:55344
    P
    pam_yubico on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28525
    P
    Security update for wget (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54349
    P
    patch on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27790
    P
    Security update for mozilla-nss
    2020-12-01
    oval:org.opensuse.security:def:29847
    P
    Security update for Linux kernel
    2020-12-01
    oval:org.opensuse.security:def:25773
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:27602
    P
    Security update for bind
    2020-12-01
    oval:org.opensuse.security:def:29062
    P
    Security update for bsdtar (Important)
    2020-12-01
    oval:org.opensuse.security:def:54923
    P
    libruby2_1-2_1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34283
    P
    Security update for python (Important)
    2020-12-01
    oval:org.opensuse.security:def:30522
    P
    Security update for hplip
    2020-12-01
    oval:org.opensuse.security:def:54499
    P
    iputils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33286
    P
    wpa_supplicant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26274
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:27978
    P
    Security update for MozillaFirefox (Critical)
    2020-12-01
    oval:org.opensuse.security:def:33508
    P
    Security update for OpenSSL
    2020-12-01
    oval:org.opensuse.security:def:27314
    P
    vino on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55680
    P
    Security update for openssl (Important)
    2020-12-01
    oval:org.opensuse.security:def:32434
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:27259
    P
    pam_mount on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29582
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26473
    P
    Security update for Chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:33834
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27741
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:29803
    P
    Security update for inn (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25709
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:27545
    P
    python-imaging on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27146
    P
    hplip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29051
    P
    Security update for atftp (Important)
    2020-12-01
    oval:org.opensuse.security:def:34244
    P
    Security update for PostgreSQL
    2020-12-01
    oval:org.opensuse.security:def:28674
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:54498
    P
    imobiledevice-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33151
    P
    libgcrypt11 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27939
    P
    Security update for GraphicsMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30303
    P
    Security update for sudo (Important)
    2020-12-01
    oval:org.opensuse.security:def:27186
    P
    libgcrypt11 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55588
    P
    Security update for net-snmp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32390
    P
    Security update for tomcat6 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29510
    P
    Security update for ImageMagick (Low)
    2020-12-01
    oval:org.opensuse.security:def:55072
    P
    ceph-common on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26429
    P
    Security update for keepalived (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30978
    P
    Security update for hplip
    2020-12-01
    oval:org.opensuse.security:def:27688
    P
    Security update for xorg-x11-libXfixes
    2020-12-01
    oval:org.opensuse.security:def:29785
    P
    Security update for gpg2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57298
    P
    Security update for augeas (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25698
    P
    Security update for dpdk (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27463
    P
    libmysql55client_r18-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29944
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:29050
    P
    Security update for apache2-mod_perl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54512
    P
    libIlmImf-Imf_2_1-21 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31981
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:34195
    P
    Security update for pango
    2020-12-01
    oval:org.opensuse.security:def:27887
    P
    Security update for rubygem-rack-1_4 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27890
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:27122
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55480
    P
    Security update for compat-openssl098 (Important)
    2020-12-01
    oval:org.opensuse.security:def:32368
    P
    Security update for tar (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28560
    P
    Security update for hplip
    2020-12-01
    oval:org.opensuse.security:def:29499
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54899
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33526
    P
    Security update for w3m
    2020-12-01
    oval:org.opensuse.security:def:26415
    P
    Security update for python-Django (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30485
    P
    Security update for coreutils
    2020-12-01
    oval:org.opensuse.security:def:33602
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:27537
    P
    popt-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29746
    P
    Security update for gd
    2020-12-01
    oval:org.opensuse.security:def:25697
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27335
    P
    xorg-x11-libXv-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29858
    P
    Security update for Linux Kernel
    2020-12-01
    oval:org.opensuse.security:def:55737
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:33852
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54372
    P
    rhythmbox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31924
    P
    Security update for ghostscript-library (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34137
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27843
    P
    Security update for net-snmp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57223
    P
    Security update for hplip
    2020-12-01
    oval:org.opensuse.security:def:25982
    P
    Security update for bash (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27837
    P
    Security update for mozilla-nss (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27111
    P
    dnsmasq on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29262
    P
    Security update for wget (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32329
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34352
    P
    Security update for strongswan (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29498
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54661
    P
    python-cupshelpers on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33438
    P
    Security update for dnsmasq
    2020-12-01
    oval:org.opensuse.security:def:26376
    P
    Security update for MozillaThunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28036
    P
    Security update for bzr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33520
    P
    Security update for squid
    2020-12-01
    oval:org.opensuse.security:def:27453
    P
    libid3tag on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29697
    P
    Security update for facter (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55792
    P
    Security update for fontconfig (Low)
    2020-12-01
    oval:org.opensuse.security:def:35030
    P
    Security update for hplip
    2020-12-01
    oval:org.opensuse.security:def:27271
    P
    ppc64-diag on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29801
    P
    Security update for icu (Important)
    2020-12-01
    oval:org.opensuse.security:def:55629
    P
    Security update for libpng16 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33828
    P
    Security update for gnuplot (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28709
    P
    Security update for hplip
    2020-12-01
    oval:org.opensuse.security:def:54350
    P
    pcsc-ccid on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31832
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:27829
    P
    Security update for libyaml
    2020-12-01
    oval:org.opensuse.security:def:30941
    P
    Security update for glibc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25901
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:27686
    P
    Security update for xorg-x11-libX11
    2020-12-01
    oval:org.opensuse.security:def:27110
    P
    dhcpcd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29131
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:55029
    P
    vino on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34308
    P
    Security update for quota
    2020-12-01
    oval:org.opensuse.security:def:54521
    P
    libXi6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33381
    P
    Security update for clamsap (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26327
    P
    Security update for Chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:27992
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:57372
    P
    Security update for hplip
    2020-12-01
    oval:org.opensuse.security:def:33509
    P
    Security update for openswan
    2020-12-01
    oval:org.opensuse.security:def:27396
    P
    evolution-data-server-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29643
    P
    Security update for cups (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55754
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:34990
    P
    Security update for glibc
    2020-12-01
    oval:org.mitre.oval:def:25362
    P
    SUSE-SU-2014:0188-1 -- Security update for hplip
    2014-09-08
    oval:org.mitre.oval:def:25107
    P
    SUSE-SU-2014:0188-2 -- Security update for hplip
    2014-09-08
    oval:org.mitre.oval:def:20191
    P
    DSA-2829-1 hplip - several
    2014-07-21
    oval:org.mitre.oval:def:18804
    P
    USN-1981-1 -- hplip vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:23116
    P
    ELSA-2013:0500: hplip security, bug fix and enhancement update (Low)
    2014-05-26
    oval:org.mitre.oval:def:20979
    P
    RHSA-2013:0500: hplip security, bug fix and enhancement update (Low)
    2014-02-17
    oval:org.opensuse.security:def:79857
    P
    Security update for hplip
    2014-01-17
    oval:org.opensuse.security:def:80006
    P
    Security update for hplip
    2014-01-17
    oval:com.ubuntu.precise:def:20130200000
    V
    CVE-2013-0200 on Ubuntu 12.04 LTS (precise) - medium.
    2013-03-06
    oval:com.redhat.rhsa:def:20130500
    P
    RHSA-2013:0500: hplip security, bug fix and enhancement update (Low)
    2013-02-21
    BACK
    hp hplip 2.8.2