HP OpenMail Vulnerability
BID:96
Info
HP OpenMail Vulnerability
| Bugtraq ID: | 96 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | Apr 29 1988 12:00AM |
| Updated: | Apr 29 1988 12:00AM |
| Credit: | |
| Vulnerable: |
HP OpenMail 5.10 HP OpenMail 5.1 HP OpenMail 4.1 |
| Not Vulnerable: | |
Exploit / POC
HP OpenMail Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
HP OpenMail Vulnerability
Solution:
Ref: [OpenMail Technical Guide, pages 3-366, and 3-369]
Hewlett-Packard notes that this issue has already been adequately addressed in OpenMail. There is a general parameter setting (UAL_PRINT_SERVER_ONLY) in the general.cfg file, that, if set to TRUE, forces all server printing to go through OpenMail's print server. The general customization file general.cfg is located in /var/opt/openmail/sys, as is the print server's configuration file print.cfg. On the client all that is necessary is to then change the 'Printer Server Command' to point to one of the configured printers.
OpenMail's print server uses a configuration file to configure available printers, and validates each print request against its configured printers. Any print requests that do not match the required syntax will not be executed.
More information about OpenMail's print server and how to configure it can be found in the OpenMail Technical Guide (pages 3-366 to 3-369 for the GR5 edition)
Solution:
Ref: [OpenMail Technical Guide, pages 3-366, and 3-369]
Hewlett-Packard notes that this issue has already been adequately addressed in OpenMail. There is a general parameter setting (UAL_PRINT_SERVER_ONLY) in the general.cfg file, that, if set to TRUE, forces all server printing to go through OpenMail's print server. The general customization file general.cfg is located in /var/opt/openmail/sys, as is the print server's configuration file print.cfg. On the client all that is necessary is to then change the 'Printer Server Command' to point to one of the configured printers.
OpenMail's print server uses a configuration file to configure available printers, and validates each print request against its configured printers. Any print requests that do not match the required syntax will not be executed.
More information about OpenMail's print server and how to configure it can be found in the OpenMail Technical Guide (pages 3-366 to 3-369 for the GR5 edition)
References
HP OpenMail Vulnerability
References:
References: