HP Color LaserJet Toolbox Software Lets Remote Users View Files on the Target System
|
|
SecurityTracker Alert ID: 1015862
|
|
SecurityTracker URL: http://securitytracker.com/id?1015862
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Updated: Apr 6 2006
|
Original Entry Date: Apr 4 2006
|
Impact: Disclosure of system information, Disclosure of user information
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Advisory: HP Security Bulletin
|
Version(s): Color LaserJet 2500 and 4600 Toolbox software for Windows-based systems
|
Description: A vulnerability was reported in HP Color LaserJet Toolbox software for Windows-based systems. A remote user can view arbitrary files.
The HP Color LaserJet 2500 and 4600 Toolbox software contains an unspecified vulnerability. A remote user can read arbitrary files
on the target system.
A demonstration exploit URL is provided:
http://[target]:5225/../../../boot.ini
This vulnerability
affects Windows-based software that accompanies the HP Color LaserJet 2500 and Color LaserJet 4600. The actual printers are not
affected.
Sec-1 discovered this vulnerability.
|
Impact: A remote user can view files on the target system.
|
Solution: The vendor has issued "HP Color LaserJet 2500/4600 Software Update" version 3.1 to fix the vulnerability.
The vendor's advisory is available at:
http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00634759
|
Vendor URL: www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00634759 (Links to External Site)
|
Cause: Access control error
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 4 Apr 2006 00:20:48 -0400
Subject: HPSBPI2109 SSRT061141 rev.1 - HP Color LaserJet 2500 and 4600 Toolbox Running on Microsoft Windows Remote Unauthorized Disclosure of Information
|
http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00634759
|
|