Debian Security Advisory
DSA-2829-1 hplip -- several vulnerabilities
- Date Reported:
- 28 Dec 2013
- Affected Packages:
- hplip
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2013-0200, CVE-2013-4325, CVE-2013-6402, CVE-2013-6427.
- More information:
-
Multiple vulnerabilities have been found in the HP Linux Printing and Imaging System: Insecure temporary files, insufficient permission checks in PackageKit and the insecure hp-upgrade service has been disabled.
For the oldstable distribution (squeeze), these problems have been fixed in version 3.10.6-2+squeeze2.
For the stable distribution (wheezy), these problems have been fixed in version 3.12.6-3.1+deb7u1.
For the unstable distribution (sid), these problems have been fixed in version 3.13.11-2.
We recommend that you upgrade your hplip packages.