CVE-2015-0839
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/08/2017
Last modified:
20/04/2025
Description
The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by leveraging use of a short GPG key id from a keyserver to verify print plugin downloads.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:hp:linux_imaging_and_printing:*:*:*:*:*:*:*:* | 3.17.7 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162442.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162880.html
- http://www.openwall.com/lists/oss-security/2015/05/29/2
- http://www.securityfocus.com/bid/74913
- http://www.ubuntu.com/usn/USN-2699-1
- https://bugs.launchpad.net/hplip/+bug/1432516
- https://bugzilla.redhat.com/show_bug.cgi?id=1227252
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162442.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162880.html
- http://www.openwall.com/lists/oss-security/2015/05/29/2
- http://www.securityfocus.com/bid/74913
- http://www.ubuntu.com/usn/USN-2699-1
- https://bugs.launchpad.net/hplip/+bug/1432516
- https://bugzilla.redhat.com/show_bug.cgi?id=1227252