Secunia Security Advisory - A vulnerability has been reported in HP MFP Digital Sending Software, which can be exploited by malicious people with local access to bypass certain security restrictions.
2f2fd428359122af02df87b1a657e7cd15a205f1084aa199c64af3cd3baada94
----------------------------------------------------------------------
Looking for a job?
Secunia is hiring skilled researchers and talented developers.
http://secunia.com/company/jobs/
----------------------------------------------------------------------
TITLE:
HP MFP Digital Sending Software Unauthorised Access
SECUNIA ADVISORY ID:
SA39825
VERIFY ADVISORY:
http://secunia.com/advisories/39825/
DESCRIPTION:
A vulnerability has been reported in HP MFP Digital Sending Software,
which can be exploited by malicious people with local access to bypass
certain security restrictions.
The vulnerability is caused due to an unspecified error, which can be
exploited to gain unauthorised access to functionality (e.g. "Send to
e-mail") of an HP Multifunction Peripheral (MFP) controlled by the HP
Digital Sending Software.
The vulnerability is reported in HP MFP Digital Sending Software
prior to version 4.18.3 running on Windows.
SOLUTION:
Update to HP MFP Digital Sending Software version 4.18.3.
HP MFP Digital Sending Software v4.18.3 File (dss4183.zip):
SHA1: 1b81-94a7-8a8e-d12e-f2e9-038e-2de2-c9a1-daa5-c32c
ftp://ftp.usa.hp.com (user:dss4183 / password:Costing9)
PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.
ORIGINAL ADVISORY:
HPSBPI02532 SSRT100111:
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02161624
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
private users keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------