- Description
- hplip.postinst in HP Linux Imaging and Printing (HPLIP) 2.7.7 and 2.8.2 on Ubuntu allows local users to change the ownership of arbitrary files via unspecified manipulations in advance of an HPLIP installation or upgrade by an administrator, related to the product's attempt to correct the ownership of its configuration files within home directories.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 6.9
- Impact score
- 10
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:C/I:C/A:C
- nvd@nist.gov
- CWE-264
- Hype score
- Not currently trending
- Red HatNot vulnerable. This issue did not affect the versions of hplip as shipped with Red Hat Enterprise Linux 5.
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hp:hplip:2.7.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ED2C0484-7995-488C-BF9D-61A4EC318F92"
},
{
"criteria": "cpe:2.3:a:hp:hplip:2.8.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "205AA0F1-796F-49EA-933F-245B558F4C3B"
}
],
"operator": "OR"
}
]
}
]