Advertisement
Promo

Security threats Toolkit

HP patches 'critical' flaw in 100 laptop models

Liam Tung ZDNet Australia

Published: 18 Dec 2007 13:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

HP has released a patch which disables its Info Center shortcut tool, used in 100 different HP laptop models, in an attempt to work around a design flaw.

HP has labelled the flaw "critical". It affects 15 variations of HP's Compaq Presario Notebook PC series, three in the HP 500 Notebook model series, 46 in the HP Compaq Notebook PC series, and 14 in the HP Pavilion Notebook PC series, as well as other models, according to HP's security notice.

News of the flaw was reported by a researcher using the name "porkythepig" on the Bugtraq security bulletin on 11 December. The researcher discovered that flaws in HPInfoDLL.dll — one of the ActiveX controls used within HP Info Center — could allow remote attackers to carry out a number of malicious activities.

These include installing malware, changing registry information in preparation for a more sophisticated attack, using the machine in a denial-of-service attack and stealing sensitive data from documents on the compromised machine.

For the flaw to be exploited, the user of an affected laptop would need to visit a specially crafted website.

Exploit code has been posted on vulnerability-alert site milw0rm and on SecurityFocus's Bugtraq.

CNET News.com's Robert Vamosi and ZDNet.co.uk's Tom Espiner contributed to this article.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
18 out of 21 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters