MGASA-2015-0336
Dashboard / Vulnerabilities / MGASA-2015-0336
Summary: Updated hplip packages fix CVE-2015-0839
Details: Updated hplip packages fix security vulnerability: It was reported that the hp-plugin utility, included in the hplip package, downloads a binary driver and verifies it via a key specified by the key's short ID. A man-in-the-middle attacker could use this flaw to generate a key with the expected short ID and trick a user into downloading a malicious binary (CVE-2015-0839).
References: https://advisories.mageia.org/MGASA-2015-0336.html, https://bugs.mageia.org/show_bug.cgi?id=16498, https://lists.fedoraproject.org/pipermail/package-announce/2015-July/162442.html
Affected packages
Package
Name: hplip
Purl: pkg:rpm/mageia/hplip?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
