Advertisement
Promo

Security threats Toolkit

Printer flaw opens files to prying eyes

Joris Evers CNET News

Published: 06 Apr 2006 09:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security flaw in software that ships with two HP Color LaserJet printers could open a door for cybersnoops, HP has warned.

The vulnerability lies in the Toolbox software that comes with HP's Color LaserJet 2500 and 4600 printers, the company said. The flaw could allow a remote, unauthorised user to retrieve arbitrary files from a Windows computer when the software is running in the default configuration, HP said in a security alert published on Sunday.

The Toolbox is software that installs on a PC along with the drivers. It uses a simple Web browser interface for access to printer status information, troubleshooting tips and demos, and an alerts feature.

HP has made HP Color LaserJet 2500/4600 Software Update version 3.1 available to resolve the security issue, it said. Security monitoring company Secunia rates the issue "less critical". The flaw is caused by an input validation error in the Web server that's part of the software, according to a Secunia alert, published on Wednesday.

Discovery of the flaw is credited by HP and Secunia to Richard Horsman of Sec-1.com

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
265 out of 350 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters