Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
https://rhn.redhat.com/errata/RHSA-2008-0818.html
http://secunia.com/advisories/31470
http://www.vuxml.org/freebsd/37940643-be1b-11dd-a578-0030843d3802.html
Insight
The following package is affected: hplip
CVE-2008-2940
The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message.
CVE-2008-2941
The hpssd message parser in hpssd.py in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to cause a denial of service (process stop) via a crafted packet, as demonstrated by sending 'msg=0' to TCP port 2207.
Severity
Classification
-
CVE CVE-2008-2940, CVE-2008-2941 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities