VDB
CVE-2011-2722
CVE-2011-2722
PUBLISHED
CVSS 1.2000000476837158 LOW
The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out temporary file.
EPSS 0.44% · 36.2th percentile
Risk Scores
CVSS 2.0
1.2000000476837158
EPSS Score
0.44%
36.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| hp | linux_imaging_and_printing_project | 3.9.10, 0, 3.9.4 |
| n/a | n/a | n/a |
Timeline
- May 25, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 12, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- May 29, 2023 EPSS Score
References
- USN-1981-1 vendor-advisory
- http://hplipopensource.com/hplip-web/release_notes.html patch
- https://bugzilla.redhat.com/attachment.cgi?id=515866&action=diff technical
- http://rhn.redhat.com/errata/RHSA-2013-0133.html technical
- http://secunia.com/advisories/55083 technical
- http://security.gentoo.org/glsa/glsa-201203-17.xml technical
- http://www.openwall.com/lists/oss-security/2011/07/26/14 technical
- https://bugzilla.novell.com/show_bug.cgi?id=704608 technical
- https://nvd.nist.gov/vuln/detail/CVE-2011-2722 advisory
- https://access.redhat.com/errata/RHSA-2013:0133 url
- https://access.redhat.com/errata/RHSA-2013:0500 url
- https://access.redhat.com/security/cve/CVE-2011-2722 url
- https://bugs.launchpad.net/hplip/+bug/809904 url
- https://bugzilla.redhat.com/show_bug.cgi?id=725830 url
- http://secunia.com/advisories/48441 url