CVE-2013-0200

Publication date 6 March 2013

Last updated 24 July 2024


Ubuntu priority

HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.

Read the notes from the security team

Status

Package Ubuntu Release Status
hplip 13.04 raring
Not affected
12.10 quantal
Fixed 3.12.6-3ubuntu4.2
12.04 LTS precise
Fixed 3.12.2-1ubuntu3.3
11.10 oneiric Ignored end of life
10.04 LTS lucid
Fixed 3.10.2-2ubuntu2.4
8.04 LTS hardy Ignored end of life

Notes


mdeslaur

possibly related bugs: https://bugzilla.redhat.com/show_bug.cgi?id=830630 https://bugs.launchpad.net/hplip/+bug/1016507

References

Related Ubuntu Security Notices (USN)

    • USN-1981-1
    • HPLIP vulnerabilities
    • 30 September 2013

Other references