CVE-2009-0122
hplip.postinst in HP Linux Imaging and Printing (HPLIP) 2.7.7 and 2.8.2 on Ubuntu allows local users to change the ownership of arbitrary files via unspecified manipulations in advance of an HPLIP installation or upgrade by an administrator, related to…
Does this matter?
Lower severity and a low EPSS score (0.51%). Track it; it rarely justifies an emergency change on its own.
Description
hplip.postinst in HP Linux Imaging and Printing (HPLIP) 2.7.7 and 2.8.2 on Ubuntu allows local users to change the ownership of arbitrary files via unspecified manipulations in advance of an HPLIP installation or upgrade by an administrator, related to the product's attempt to correct the ownership of its configuration files within home directories.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- hp/hplip
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/33539
- http://www.securityfocus.com/bid/33249Patch
- http://www.ubuntu.com/usn/usn-708-1
- https://launchpad.net/bugs/191299Exploit
- http://secunia.com/advisories/33539
- http://www.securityfocus.com/bid/33249Patch
- http://www.ubuntu.com/usn/usn-708-1
- https://launchpad.net/bugs/191299Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.