CVE-2008-2940

EUVD-2008-2932
The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
hplinux_imaging_and_printing_project
1.6.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
hplip
bookworm
3.22.10+dfsg0-2
fixed
bullseye
3.21.2+dfsg1-2
fixed
etch
no-dsa
sid
3.22.10+dfsg0-5.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
hplip
dapper
Fixed 0.9.7-4ubuntu1.1
released
feisty
ignored
gutsy
Fixed 2.7.7.dfsg.1-0ubuntu5.1
released
hardy
Fixed 2.8.2-0ubuntu8.1
released
intrepid
not-affected
Common Weakness Enumeration