int(4469)

Vulnerability Bulletins


Acceso no autorizado en algunas HP LaserJet Printers, Color LaserJet Printers y Digital Senders

Vulnerability classification

Property Value
Confidence level Oficial
Impact Aumento de privilegios
Dificulty Experto
Required attacker level Acceso remoto con cuenta

System information

Property Value
Affected manufacturer Comercial Software
Affected software HP LaserJet 2410 / firmware anterior a 20080819 SPCL112A
HP LaserJet 2420 / firmware anterior a 20080819 SPCL112A
HP LaserJet 2430 / firmware anterior a 20080819 SPCL112A
HP LaserJet 4250 / firmware anterior a 20080819 SPCL015A
HP LaserJet 4350 / firmware anterior a 20080819 SPCL015A
HP LaserJet 5200 / firmware anterior a 20090305 SPCL0601A
HP LaserJet 9040 / firmware anterior a 20080819 SPCL110A
HP LaserJet 9050 / firmware anterior a 20080819 SPCL110A
HP LaserJet 4345mfp / firmware anterior a 09.120.9
HP Color LaserJet 4730mfp / firmware anterior a 46.200.9
HP LaserJet 9040mfp / firmware anterior a 08.110.9
HP LaserJet 9050mfp / firmware anterior a 08.110.9
HP 9200C Digital Sender / firmware anterior a 09.120.9
HP Color LaserJet 9500mfp / firmware anterior a 08.110.9

Description

Se ha descubierto una vulnerabilidad de tipo salto de directorio en la interfaz de administrador web de HP JetDirect.

Un atacante remoto podría acceder a ficheros arbitrarios mediante URIs especialmente diseñadas.

Solution



Actualización de software

Hewlett-Packard (HPSBPI02398)
HP LaserJet 4345mfp / firmware 09.120.9 o posterior
HP Color LaserJet 4730mfp / firmware 46.200.9 o posterior
HP LaserJet 9040mfp / firmware 08.110.9 o posterior
HP LaserJet 9050mfp / firmware 08.110.9 o posterior
HP 9200C Digital Sender / firmware 09.120.9 o posterior
HP Color LaserJet 9500mfp / firmware 08.110.9 o posterior
HP LaserJet 2410 / firmware lj24x0fw_08_112_spcl112A-1.rfu
HP LaserJet 2420 / firmware lj24x0fw_08_112_spcl112A-1.rfu
HP LaserJet 2430 / firmware lj24x0fw_08_112_spcl112A-1.rfu
HP LaserJet 4250 / firmware lj4x50fw_08_015_spcl015A.rfu
HP LaserJet 4350 / firmware lj4x50fw_08_015_spcl015A.rfu
HP LaserJet 9040 / firmware lj9040-50fw_08_110_spcl110A-1.rfu
HP LaserJet 9050 / firmware lj9040-50fw_08_110_spcl110A-1.rfu
HP LaserJet 5200 / firmware lj5200fw_08_060_1_interim.rfu

Standar resources

Property Value
CVE CVE-2008-4419
BID

Other resources

HP SECURITY BULLETIN (HPSBPI02398)
http://www13.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01623905-1

HP SECURITY BULLETIN (HPSBPI02398)
http://www13.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01623905-2

HP SECURITY BULLETIN (HPSBPI02398)
http://www13.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01623905-3

HP SECURITY BULLETIN (HPSBPI02398)
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01623905-5

Version history

Version Comments Date
1.0 Aviso emitido 2009-02-09
1.1 Aviso actualizado por HP (HPSBPI02398) 2009-02-17
1.2 Aviso actualizado por HP (HPSBPI02398) 2009-05-21
1.3 Aviso actualizado por HP (HPSBPI02398) 2009-07-06