HP Linux Imaging and Printing System HSSPD.PY Daemon Arbitrary Command Execution Vulnerability
BID:26054
Info
HP Linux Imaging and Printing System HSSPD.PY Daemon Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 26054 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-5208 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2007 12:00AM |
| Updated: | Mar 19 2015 09:36AM |
| Credit: | Kees Cook of the Ubuntu Security Team discovered this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 SuSE SUSE Linux Enterprise Desktop 10 SuSE Linux 10.3 SuSE Linux 10.2 S.u.S.E. Linux 10.1 S.u.S.E. Linux 10.0 Red Hat Fedora Core7 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 HP Linux Imaging and Printing System 2.7.9 HP Linux Imaging and Printing System 2.7.7 HP Linux Imaging and Printing System 2.7.6 HP Linux Imaging and Printing System 2.7.4 HP Linux Imaging and Printing System 2.7.2 HP Linux Imaging and Printing System 2.7.1 HP Linux Imaging and Printing System 1.7.4 HP Linux Imaging and Printing System 1.7.3 HP Linux Imaging and Printing System 1.7.2 HP Linux Imaging and Printing System 1.7.1 HP Linux Imaging and Printing System 1.6.12 HP Linux Imaging and Printing System 1.6.10 HP Linux Imaging and Printing System 1.6.9 HP Linux Imaging and Printing System 1.6.7 HP Linux Imaging and Printing System 1.6.6 HP Linux Imaging and Printing System 2.7.6-1.patch HP Linux Imaging and Printing System 1.7.4a HP Linux Imaging and Printing System 1.6.6a Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
HP Linux Imaging and Printing System HSSPD.PY Daemon Arbitrary Command Execution Vulnerability
HP Linux Imaging and Printing System (HPLIP) is prone to an arbitrary command-execution vulnerability because it fails to adequately sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary commands with superuser privileges. Successful attacks will completely compromise affected computers.
NOTE: By default the application's 'hpssd' daemon listens only on localhost, but it can be configured (via /etc/hp/hplip.conf) to listen to remote requests as well.
HPLIP versions in the 1.0 and 2.0 series are vulnerable.
HP Linux Imaging and Printing System (HPLIP) is prone to an arbitrary command-execution vulnerability because it fails to adequately sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary commands with superuser privileges. Successful attacks will completely compromise affected computers.
NOTE: By default the application's 'hpssd' daemon listens only on localhost, but it can be configured (via /etc/hp/hplip.conf) to listen to remote requests as well.
HPLIP versions in the 1.0 and 2.0 series are vulnerable.
Exploit / POC
HP Linux Imaging and Printing System HSSPD.PY Daemon Arbitrary Command Execution Vulnerability
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
HP Linux Imaging and Printing System HSSPD.PY Daemon Arbitrary Command Execution Vulnerability
Solution:
Fixes are available to address this issue. Please see the references for more information.
Ubuntu Ubuntu Linux 6.10 sparc
Ubuntu Ubuntu Linux 6.10 powerpc
Ubuntu Ubuntu Linux 6.10 i386
Ubuntu Ubuntu Linux 7.04 amd64
Ubuntu Ubuntu Linux 6.10 amd64
Ubuntu Ubuntu Linux 7.04 i386
Ubuntu Ubuntu Linux 7.04 powerpc
Ubuntu Ubuntu Linux 7.04 sparc
Solution:
Fixes are available to address this issue. Please see the references for more information.
Ubuntu Ubuntu Linux 6.10 sparc
-
Ubuntu hpijs_2.6.9+1.6.9-0ubuntu2.1_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/h/hplip/hpijs_2.6.9+1.6.9- 0ubuntu2.1_sparc.deb
Ubuntu Ubuntu Linux 6.10 powerpc
-
Ubuntu hpijs_2.6.9+1.6.9-0ubuntu2.1_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/h/hplip/hpijs_2.6.9+1.6.9- 0ubuntu2.1_powerpc.deb
Ubuntu Ubuntu Linux 6.10 i386
-
Ubuntu hpijs_2.6.9+1.6.9-0ubuntu2.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/h/hplip/hpijs_2.6.9+1.6.9- 0ubuntu2.1_i386.deb
Ubuntu Ubuntu Linux 7.04 amd64
-
Ubuntu hpijs_2.7.2+1.7.3-0ubuntu1.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/h/hplip/hpijs_2.7.2+1.7.3- 0ubuntu1.1_amd64.deb
Ubuntu Ubuntu Linux 6.10 amd64
-
Ubuntu hpijs_2.6.9+1.6.9-0ubuntu2.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/h/hplip/hpijs_2.6.9+1.6.9- 0ubuntu2.1_amd64.deb
Ubuntu Ubuntu Linux 7.04 i386
-
Ubuntu hpijs_2.7.2+1.7.3-0ubuntu1.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/h/hplip/hpijs_2.7.2+1.7.3- 0ubuntu1.1_i386.deb
Ubuntu Ubuntu Linux 7.04 powerpc
-
Ubuntu hpijs_2.7.2+1.7.3-0ubuntu1.1_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/h/hplip/hpijs_2.7.2+1.7.3- 0ubuntu1.1_powerpc.deb
Ubuntu Ubuntu Linux 7.04 sparc
-
Ubuntu hpijs_2.7.2+1.7.3-0ubuntu1.1_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/h/hplip/hpijs_2.7.2+1.7.3- 0ubuntu1.1_sparc.deb
References
HP Linux Imaging and Printing System HSSPD.PY Daemon Arbitrary Command Execution Vulnerability
References:
References: