CVE-2013-6402

Publication date 5 January 2014

Last updated 24 July 2024


Ubuntu priority

base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.11 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hp-pkservice.log temporary file.

Read the notes from the security team

Status

Package Ubuntu Release Status
hplip 13.10 saucy
Fixed 3.13.9-1ubuntu0.1
13.04 raring Ignored end of life
12.10 quantal
Fixed 3.12.6-3ubuntu4.3
12.04 LTS precise
Fixed 3.12.2-1ubuntu3.4
10.04 LTS lucid
Fixed 3.10.2-2ubuntu2.5

Notes


mdeslaur

mitigated by symlink restrictions (except in lucid)

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
hplip

References

Related Ubuntu Security Notices (USN)

    • USN-2085-1
    • HPLIP vulnerabilities
    • 21 January 2014

Other references