Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 20 Nov 2023 14:39:02 +0100
From: Matthias Gerstner <mgerstner@...e.de>
To: oss-security@...ts.openwall.com
Subject: Re: hplip: security issues in `hpps` program due to
 fixed /tmp path usage in prnt/hpps/hppsfilter.c

Hi,

thank you both for your suggestions. I just reached out to
hp-security-alert@...com about this.

There are a couple of other hplip issues I know of that have also been
left unattended for a long time that I mentioned there as well.

Best Regards

Matthias

On Sun, Nov 19, 2023 at 07:11:37AM -0500, Mike O'Connor wrote:
> [removing security@....com from the Cc:]
> 
> This is for hp.com product security, not hpe.com.  HP and HPE are two
> separate companies, and HPE isn't the printer company.  
> 
> To report a potential security vulnerability with a HP product,
> contact: hp-security-alert@...com
> 
> Both HPE and HP are CVE CNAs.  Here's HP's CVE CNA information:
> https://www.cve.org/PartnerInformation/ListofPartners/partner/hp
> 
> 
> HTH,
> -Mike
> 
> 
> :Thanks for making the community aware of this issue.
> :
> :Perhaps security@....com can help to route internally to get a CVE issued
> :and find the appropriate owners to fix.

Download attachment "signature.asc" of type "application/pgp-signature" (834 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.