A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data.
The vulnerability results from an integer overflow error (CWE-190) in the hpcups component responsible for processing print data, leading to heap-based buffer overflow (CWE-122). An attacker can send specially crafted print data that triggers incorrect buffer size calculations, resulting in out-of-bounds write. The attack vector is network-based, requires no authentication or user interaction, significantly increasing the risk of vulnerability exploitation.
Successful exploitation of the vulnerability may allow an attacker to escalate privileges on the system and execute arbitrary code (RCE) in the context of the printing service process.
Patches available from the vendor should be applied in accordance with the references (HP security bulletin HPSBPI04118). It is recommended to monitor the official HP support channel at https://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118 to obtain updated versions of HPLIP software.
HP Linux Imaging and Printing Software (HPLIP) — specific versions indicated in vendor references (https://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHP Linux Imaging And Printing
APPHp< 3.26.4
Related vulnerabilities
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This pot...
The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers...
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documenta...
RCE w Apache Struts 2 poprzez błędną obsługę nagłówków HTTP (Jakarta Multipart parser)
RCE w Adobe Flash Player — heap-based buffer overflow (CVE-2015-3113)