HPLIP: Multiple vulnerabilities Multiple vulnerabilities have been found in HPLIP, the worst of which may allow execution of arbitrary code. hplip 2012-03-16 2012-03-16 352085 388655 local, remote 3.11.10 3.11.10

The Hewlett-Packard Linux Imaging and Printing system (HPLIP) provides drivers for HP's inkjet and laser printers, scanners and fax machines.

Two vulnerabilities have been found in HPLIP:

A remote attacker might send specially crafted SNMP reponses, possibly resulting in execution of arbitrary code or a Denial of Service condition. Furthermore, a local attacker could perform symlink attacks to overwrite arbitrary files.

There is no known workaround at this time.

All HPLIP users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-print/hplip-3.11.10"
CVE-2010-4267 CVE-2011-2722 underling ackle