U radu programskog paketa HP MFP Digital Sending Software, na operacijskim sustavima Windows, uočen je sigurnosni propust kojeg zloćudni korisnik može iskoristiti za otkrivanje osjetljivih podataka.
Paket:
HP MFP Digital Sending Software (DSS) 4.x
Operacijski sustavi:
Microsoft Windows XP, Microsoft Windows Server 2003, Microsoft Windows Vista, Microsoft Windows Server 2008, Microsoft Windows 7
Kritičnost:
1.2
Problem:
nepoznat
Iskorištavanje:
lokalno
Posljedica:
otkrivanje osjetljivih informacija
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2011-3163
Izvorni ID preporuke:
HPSBPI02711
Izvor:
Hewlett Packard
Problem:
Problem sigurnosti se javlja zbog nespecificirane ranjivosti.
Posljedica:
Navedenu ranjivost napadač može iskoristiti za otkrivanje osjetljivih korisničkih podataka.
Rješenje:
Svim se korisnicima navedenog programskog paketa savjetuje korištenje dostupnih programskih zakrpa.
SUPPORT COMMUNICATION - SECURITY BULLETIN
Document ID: c03052686
Version: 1
HPSBPI02711 SSRT100647 rev.1 - HP MFP Digital Sending Software Running on Windows, Local Information Disclosure
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.
Release Date: 2011-10-19
Last Updated: 2011-10-19
Potential Security Impact: Local information disclosure
Source: Hewlett-Packard Company, HP Software Security Response Team
VULNERABILITY SUMMARY
A potential security vulnerability has been identified with HP MFP Digital Sending Software running on Windows. The vulnerability could result in disclosure of personal information contained in workflow metadata to unintended recipients.
References: CVE-2011-3163
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
HP MFP Digital Sending Software v4.91.21 and all previous 4.9x versions
BACKGROUND
For a PGP signed version of this security bulletin please write to: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
CVSS 2.0 Base Metrics
Reference
Base Vector
Base Score
CVE-2011-3163
(AV:L/AC:H/Au:N/C:P/I:N/A:N)
1.2
Information on CVSS is documented in HP Customer Notice: HPSN-2008-002.
RESOLUTION
HP has provided HP MFP Digital Sending Software v4.20 to resolve the vulnerability.
HP MFP Digital Sending Software v4.20 can be downloaded from http://www.hp.com/go/dss
Note: Select "DSS 4 free 60-day demo."
HISTORY
Version:1 (rev.1) - 19 October 2011 Initial release
Posljednje sigurnosne preporuke