CVE-2011-2722 – hplip: insecure temporary file handling
https://notcve.org/view.php?id=CVE-2011-2722
The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out temporary file. La función send_data_to_stdout en prnt/hpijs/hpcupsfax.cpp en HP Linux Imaging y Printing (HPLIP) v3.x anterior a v3.11.10 permite a usuarios locales sobreescribir ficheros arbitrarios mediante un ataque de enlaces simbólicos sobre el fichero temporal /tmp/hpcupsfax.out • http://hplipopensource.com/hplip-web/release_notes.html http://rhn.redhat.com/errata/RHSA-2013-0133.html http://secunia.com/advisories/48441 http://secunia.com/advisories/55083 http://security.gentoo.org/glsa/glsa-201203-17.xml http://www.openwall.com/lists/oss-security/2011/07/26/14 http://www.ubuntu.com/usn/USN-1981-1 https://bugs.launchpad.net/hplip/+bug/809904 https://bugzilla.novell.com/show_bug.cgi?id=704608 https://bugzilla.redhat.com/attachment.cgi?id • CWE-59: Improper Link Resolution Before File Access ('Link Following') CWE-377: Insecure Temporary File •
CVE-2011-2697 – foomatic: Improper sanitization of command line option in foomatic-rip
https://notcve.org/view.php?id=CVE-2011-2697
foomatic-rip-hplip in HP Linux Imaging and Printing (HPLIP) 3.11.5 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPCommandLine field in a .ppd file. foomatic-rip-hplip en HP Linux Imaging and Printing (HPLIP) v3.11.5 permite a atacantes remotos ejecutar código de su elección a través de un campo *FoomaticRIPCommandLine debidamente modificado en un archivo .ppd. • http://security.gentoo.org/glsa/glsa-201203-07.xml http://www.mandriva.com/security/advisories?name=MDVSA-2011:125 http://www.openwall.com/lists/oss-security/2011/07/13/3 http://www.openwall.com/lists/oss-security/2011/07/18/3 http://www.openwall.com/lists/oss-security/2011/07/28/1 http://www.ubuntu.com/usn/USN-1194-1 http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf https://bugzilla.novell.com/show_bug.cgi& • CWE-20: Improper Input Validation •