vendor:
Linux Imaging and Printing Project
by:
jduck
7.5
CVSS
HIGH
Command Execution
78
CWE
Product Name: Linux Imaging and Printing Project
Affected Version From: 1.x
Affected Version To: 2.x before 2.7.10
Patch Exists: YES
Related CWE: CVE-2007-5208
CPE: a:hewlett-packard:linux_imaging_and_printing_project
Platforms Tested: Unix
2010
hplip hpssd.py From Address Arbitrary Command Execution
This module exploits a command execution vulnerability in the hpssd.py daemon of the Hewlett-Packard Linux Imaging and Printing Project. According to MITRE, versions 1.x and 2.x before 2.7.10 are vulnerable. This module was written and tested using the Fedora 6 Linux distribution. On the test system, the daemon listens on localhost only and runs with root privileges. Although the configuration shows the daemon is to listen on port 2207, it actually listens on a dynamic port. NOTE: If the target system does not have a 'sendmail' command installed, this vulnerability cannot be exploited.
Mitigation:
Upgrade to version 2.7.10 or later.