Vulnerabilities > CVE-2015-0839 - Key Management Errors vulnerability in HP Linux Imaging and Printing 3.17.7

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
high complexity
hp
CWE-320
nessus

Summary

The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by leveraging use of a short GPG key id from a keyserver to verify print plugin downloads.

Vulnerable Configurations

Part Description Count
Application
Hp
1

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DLA-775.NASL
    descriptionCVE-2015-0839 The hplip plugin download function verifies the driver using a short-key. This is not secure because it is trivial to generate keys with arbitrary key IDs. For Debian 7
    last seen2020-03-17
    modified2017-01-03
    plugin id96191
    published2017-01-03
    reporterThis script is Copyright (C) 2017-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/96191
    titleDebian DLA-775-1 : hplip security update
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2015-11916.NASL
    descriptionfixes CVE-2015-0839 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2015-07-30
    plugin id85095
    published2015-07-30
    reporterThis script is Copyright (C) 2015-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/85095
    titleFedora 21 : hplip-3.14.10-9.fc21 (2015-11916)
  • NASL familyUbuntu Local Security Checks
    NASL idUBUNTU_USN-2699-1.NASL
    descriptionEnrico Zini discovered that HPLIP used a short GPG key ID when downloading keys from the keyserver. An attacker could possibly use this to return a different key with a duplicate short key id and perform a man-in-the-middle attack on printer plugin installations. Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id85157
    published2015-07-31
    reporterUbuntu Security Notice (C) 2015-2019 Canonical, Inc. / NASL script (C) 2015-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/85157
    titleUbuntu 12.04 LTS / 14.04 LTS / 15.04 : hplip vulnerability (USN-2699-1)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2015-11723.NASL
    descriptionNew upstream bug-fix release, which fixes CVE-2015-0839 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2015-07-29
    plugin id85063
    published2015-07-29
    reporterThis script is Copyright (C) 2015-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/85063
    titleFedora 22 : hplip-3.15.7-1.fc22 (2015-11723)