Bug 662740 (CVE-2010-4267)

Summary: CVE-2010-4267 hplip: remote stack overflow vulnerability
Product: [Other] Security Response Reporter: Vincent Danen <vdanen>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: jlieskov, security-response-team, twaugh, ykopkova
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-12-07 17:59:55 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 663472, 663473, 663474, 663475, 663476, 663477, 670252, 833909, 833911    
Bug Blocks:    
Attachments:
Description Flags
patch provided by Sebastian to correct the flaw none

Description Vincent Danen 2010-12-13 19:08:17 UTC
Sebastian Krahmer reported a flaw in how hplip discovered SNMP devices.  If
certain hplip commands were run that queried SNMP devices, and a malicious user
were able to send crafted SNMP responses, it could cause the running hplip tool
to crash or, possibly, execute arbitrary code with the privileges of the user
running the tool.

Acknowledgements:

Red Hat would like to thank Sebastian Krahmer of the SuSE Security Team for reporting this issue.

Comment 2 Vincent Danen 2010-12-13 19:11:55 UTC
Created attachment 468455 [details]
patch provided by Sebastian to correct the flaw

Comment 28 Jan Lieskovsky 2011-01-17 16:53:05 UTC
Created hplip tracking bugs for this issue

Affects: fedora-all [bug 670252]

Comment 29 errata-xmlrpc 2011-01-17 17:47:15 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5
  Red Hat Enterprise Linux 6

Via RHSA-2011:0154 https://rhn.redhat.com/errata/RHSA-2011-0154.html