exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

SEC-1-hp.txt

SEC-1-hp.txt
Posted Apr 11, 2006
Site sec-1.com

SEC-1 LTD Security Advisory: HP Colour LaserJet 2500 and 4600 Toolbox Directory Traversal Vulnerability

tags | advisory
SHA-256 | d015214a56a990d14d7faa42df0ae69e1b72be48b9e246c711341f1cb79c26cc

SEC-1-hp.txt

Change Mirror Download

SEC-1 LTD
www.sec-1.com

Security Advisory

Advisory Name: HP Colour LaserJet 2500 and 4600 Toolbox Directory
Traversal Vulnerability

Release Date: 04/04/2006
Application: HP Colour LaserJet 2500 and 4600 Toolbox
Platform: Microsoft Windows (all supported versions)
Severity: Remote Arbitrary File Access
Author: Richard Horsman
Vendor Status: Fixed
CVE Candidate: Pending
Reference: http://www.sec-1.com


Overview:

The HP Colour LaserJet 2500 and 4600 Toolbox provides links to printer
status
information, help information and tools for diagnosing and solving
problems.


Vulnerability Details:

Sec-1 has identified a security vulnerability within the HP Colour
LaserJet
2500 and 4600 Toolbox software which could allow unauthorised access to
the
file system.

The vulnerable process hosts a HTTP interface on TCP port 5225 and is
susceptible to directory traversal. An attacker would have access to any
file
the logged on user has access to within the affected file system.


Exploit:

To exploit this issue:

The following request would attempt to retrieve the c:\boot.ini file via

a standard web browser.

http://<target>:5225/../../../boot.ini

This will retrieve the boot.ini file from the affected host.

Vendor Response:

HP has made the "HP Colour LaserJet 2500/4600 Software Update"
version 3.1 available to resolve the issue.

The software update can be downloaded as follows:

For the HP Colour LaserJet 2500

1. Browse to

http://www.hp.com/go/clj2500_software
2. Select ">>Download Drivers and Software"
3. Under "Select your product" choose the printer model.
4. Under "Select operating system" choose the operating system.
5. Download the "HP Colour LaserJet 2500/4600 Software Update"
version 3.1
6. Follow the download instructions presented on the "HP Colour
LaserJet 2500/4600 Software Update" download page to run
the update.

For the HP Colour LaserJet 4600

1. Browse to

http://www.hp.com/go/clj4600_software
2. Under "Select your product" choose the printer model.
3. Under "Select operating system" choose the operating system.
4. Download the "HP Colour LaserJet 2500/4600 Software Update"
version 3.1
5. Follow the download instructions presented on the "HP Colour
LaserJet 2500/4600 Software Update" download page to run the
update.

Sec-1 specialises in the provision of network security solutions. For more information on products and services we offer visit www.sec-1.com or call 0113 257 8955.

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    0 Files
  • 8
    Nov 8th
    0 Files
  • 9
    Nov 9th
    0 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close