Bugzilla – Bug 808355
VUL-1: CVE-2013-0200: hplip*: local file overwrite via /tmp files
Last modified: 2019-05-01 16:02:47 UTC
is public, via CVE db http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0200 HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.
bugbot adjusting priority
Security-team, do you know if anyone from HPLIP upstream is involved in CVE-2013-0200? Googling for "CVE-2013-0200 site:launchpad.net" finds something for Debian and Ubuntu packages but as far as I see nothing that directly belongs to HPLIP upstream. If nobody from HPLIP upstream is already involved in CVE-2013-0200, should I file an upstream security bug to have them at least informed? Compare https://bugzilla.novell.com/show_bug.cgi?id=336658#c38 and subsequent comments how things can go wrong if upstream gets not involved right from the start. There CVE-2010-4267 exists since Dec. 2010 but is still not fixed upstream...
I did some diffing and it seems that upstream hplip (a) knows about these issues and (b) fixed them between 3.12.11 and 3.13.2.
Update released for: hplip, hplip-debuginfo, hplip-debugsource, hplip-hpijs Products: SLE-DEBUGINFO 11-SP2 (i386, ia64, ppc64, s390x, x86_64) SLE-DESKTOP 11-SP2 (i386, x86_64) SLE-SERVER 11-SP2 (i386, ia64, ppc64, s390x, x86_64) SLES4VMWARE 11-SP2 (i386, x86_64)
SUSE-SU-2014:0188-1: An update that solves three vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 808355,835827,836937,852368 CVE References: CVE-2013-0200,CVE-2013-4325,CVE-2013-6402 Sources used: SUSE Linux Enterprise Server 11 SP2 for VMware (src): hplip-3.11.10-0.6.11.1 SUSE Linux Enterprise Server 11 SP2 (src): hplip-3.11.10-0.6.11.1 SUSE Linux Enterprise Desktop 11 SP2 (src): hplip-3.11.10-0.6.11.1
SUSE-SU-2014:0188-2: An update that solves three vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 808355,835827,836937,852368 CVE References: CVE-2013-0200,CVE-2013-4325,CVE-2013-6402 Sources used: SUSE Linux Enterprise Server 11 SP3 for VMware (src): hplip-3.11.10-0.6.11.1 SUSE Linux Enterprise Server 11 SP3 (src): hplip-3.11.10-0.6.11.1 SUSE Linux Enterprise Desktop 11 SP3 (src): hplip-3.11.10-0.6.11.1
done