CVE-2011-2722
EPSS 0.07%
Description
The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out temporary file.
How to fix CVE-2011-2722
To remediate CVE-2011-2722, upgrade the affected package to a fixed version below.
- Debian/hplip—upgrade to 3.11.10-1 or later
Is CVE-2011-2722 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.11.10-1