HP urges LaserJet users to patch printers

Status
Not open for further replies.
D

DelJo63

February 6, 2009 (Computerworld) Hewlett-Packard Co. has warned owners of some of its laser printers to update their devices' firmware or risk having remote attackers access previously printed documents.

In an advisory published Wednesday, HP said users of certain LaserJet, Color LaserJet and Digital Sender models are affected, and it urged them to immediately download and install firmware upgrades.

The devices include 10 LaserJet models, ranging from the 2410 to the 9050; two Color LaserJet models; and the 9200C Digital Sender, a sheet-fed document scanner.

According to San Antonio-based Digital Defense Inc., the security company that reported the problem to HP last October, attackers can exploit a bug in the printers' Web-based control interface to "read arbitrary system configuration files, cached documents, etc."

The Computerworld article is available above.
List of affected printers
The SANS description
CVE-2008-4419
 
Status
Not open for further replies.
Back