Insecure Temporary File in hplip - #VU84107
Published: December 12, 2023
Vulnerability identifier: #VU84107
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-377
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insecure /tmp file paths inside hppsfilter booklet printing. A local user can escalate privileges on the system.
Affected software
hplip
hplip-sane-debuginfo
hplip-devel
hplip-hpijs-debuginfo
hplip-sane
hplip-hpijs
hplip-debuginfo
hplip-debugsource
hplip-scan-utils
hplip-scan-utils-debuginfo
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Desktop Applications Module
Basesystem Module
openSUSE Leap
hplip-sane-debuginfo
hplip-devel
hplip-hpijs-debuginfo
hplip-sane
hplip-hpijs
hplip-debuginfo
hplip-debugsource
hplip-scan-utils
hplip-scan-utils-debuginfo
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Desktop Applications Module
Basesystem Module
openSUSE Leap
Remediation
Install updates from vendor's website.
hplip - update to 3.21.10-150400.3.11.1
hplip-sane-debuginfo - update to 3.21.10-150400.3.11.1
hplip-devel - update to 3.21.10-150400.3.11.1
hplip-hpijs-debuginfo - update to 3.21.10-150400.3.11.1
hplip-sane - update to 3.21.10-150400.3.11.1
hplip-hpijs - update to 3.21.10-150400.3.11.1
hplip-debuginfo - update to 3.21.10-150400.3.11.1
hplip-debugsource - update to 3.21.10-150400.3.11.1
hplip-scan-utils - update to 3.21.10-150400.3.11.1
hplip-scan-utils-debuginfo - update to 3.21.10-150400.3.11.1
hplip-sane-debuginfo - update to 3.21.10-150400.3.11.1
hplip-devel - update to 3.21.10-150400.3.11.1
hplip-hpijs-debuginfo - update to 3.21.10-150400.3.11.1
hplip-sane - update to 3.21.10-150400.3.11.1
hplip-hpijs - update to 3.21.10-150400.3.11.1
hplip-debuginfo - update to 3.21.10-150400.3.11.1
hplip-debugsource - update to 3.21.10-150400.3.11.1
hplip-scan-utils - update to 3.21.10-150400.3.11.1
hplip-scan-utils-debuginfo - update to 3.21.10-150400.3.11.1