Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 30 Nov 2023 10:28:55 +1030
From: Alex Murray <alex.murray@...onical.com>
To: Matthias Gerstner <mgerstner@...e.de>, oss-security@...ts.openwall.com
Subject: Re: hplip: security issues in `hpps` program due to
 fixed /tmp path usage in prnt/hpps/hppsfilter.c

Hi Matthias

I just wanted to follow-up on this to see if a CVE was ever assigned?

Thanks,
Alex

On Mon, 2023-11-20 at 14:39:02 +0100, Matthias Gerstner wrote:

> Hi,
>
> thank you both for your suggestions. I just reached out to
> hp-security-alert@...com about this.
>
> There are a couple of other hplip issues I know of that have also been
> left unattended for a long time that I mentioned there as well.
>
> Best Regards
>
> Matthias
>
> On Sun, Nov 19, 2023 at 07:11:37AM -0500, Mike O'Connor wrote:
>> [removing security@....com from the Cc:]
>> 
>> This is for hp.com product security, not hpe.com.  HP and HPE are two
>> separate companies, and HPE isn't the printer company.  
>> 
>> To report a potential security vulnerability with a HP product,
>> contact: hp-security-alert@...com
>> 
>> Both HPE and HP are CVE CNAs.  Here's HP's CVE CNA information:
>> https://www.cve.org/PartnerInformation/ListofPartners/partner/hp
>> 
>> 
>> HTH,
>> -Mike
>> 
>> 
>> :Thanks for making the community aware of this issue.
>> :
>> :Perhaps security@....com can help to route internally to get a CVE issued
>> :and find the appropriate owners to fix.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.