CVE-2009-0122

NameCVE-2009-0122
Descriptionhplip.postinst in HP Linux Imaging and Printing (HPLIP) 2.7.7 and 2.8.2 on Ubuntu allows local users to change the ownership of arbitrary files via unspecified manipulations in advance of an HPLIP installation or upgrade by an administrator, related to the product's attempt to correct the ownership of its configuration files within home directories.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
hplip (PTS)jessie3.14.6-1+deb8u1fixed
stretch3.16.11+repack0-3fixed
buster3.18.12+dfsg0-2fixed
bullseye3.21.2+dfsg1-2fixed
bookworm3.22.10+dfsg0-2fixed
sid3.22.10+dfsg0-5.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
hplipsource(unstable)(not affected)

Notes

- hplip <not-affected> (only a bug in ubuntus postinst script, we use our own postinst which is not vulnerable)

Search for package or bug name: Reporting problems