Back to Database
Status published
Low
CVE-2013-6402
base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.11...
Vulnerability Description
base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.11 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hp-pkservice.log temporary file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-6402
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.ubuntu.com/usn/USN-2085-1
- https://bugzilla.novell.com/show_bug.cgi?id=852368
- https://security-tracker.debian.org/tracker/CVE-2013-6402
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00087.html
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725876
- http://www.debian.org/security/2013/dsa-2829
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00098.html
More from hp
View All →CVE-2022-48311
**UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet...
Unknown
0
CVE-2022-23456
Potential arbitrary file deletion vulnerability has been identified in HP...
Medium
5.5
CVE-2020-15596
The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on...
Medium
6.7
CVE-2019-19539
An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and...
Medium
5.5
CVE-2019-16240
A Buffer Overflow and Information Disclosure issue exists in HP...
Critical
9.1
Affected Vendor
Affected Software
linux imaging and printing project
Vulnerable Versions:
0, 3.9.2, 3.9.4, 3.9.4b, 3.9.6, 3.9.8, 3.9.10, 3.9.12, 3.10.2, 3.10.5, 3.10.6, 3.10.9, 3.11.1, 3.11.3, 3.11.3a, 3.11.5, 3.11.7, 3.11.10, 3.11.12, 3.12.2, 3.12.4, 3.12.6, 3.12.9, 3.12.10, 3.12.11, 3.13.2, 3.13.3, 3.13.4, 3.13.5, 3.13.6, 3.13.7, 3.13.8, 3.13.9, 3.13.10
Timeline
Official Publish:
January 5th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.