VDB
CVE-2008-2940
CVE-2008-2940
PUBLISHED
CVSS 7.199999809265137 HIGH
The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message.
EPSS 0.04% · 13.9th percentile
Risk Scores
CVSS 2.0
7.199999809265137
EPSS Score
0.04%
13.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| hp | linux_imaging_and_printing_project | 1.6.7 |
| n/a | n/a | n/a |
Timeline
- Aug 14, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- http://securitytracker.com/id?1020684 technical
- hplip-alertmailing-privilege-escalation(44441) vdb
- 30683 vdb
- oval:org.mitre.oval:def:10136 vdb
- 31470 third-party-advisory
- MDVSA-2008:169 vendor-advisory
- SUSE-SR:2008:021 vendor-advisory
- USN-674-1 vendor-advisory
- USN-674-2 vendor-advisory
- 32792 third-party-advisory
- 31499 third-party-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=455235 url
- 32316 third-party-advisory
- RHSA-2008:0818 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2008-2940 advisory