HIGH · 7.2

CVE-2008-2940

The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalert...

Vulnerability Description

The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
HpLinux Imaging And Printing Project1.6.7

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-2940?

CVE-2008-2940 is a vulnerability with a CVSS score of 7.2 (HIGH). The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalert...

How severe is CVE-2008-2940?

CVE-2008-2940 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-2940?

Check the references section above for vendor advisories and patch information. Affected products include: Hp Linux Imaging And Printing Project.