ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

HP patches 'critical' flaw in 100 laptop models

Liam Tung ZDNet Australia

Published: 18 Dec 2007 13:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

HP has released a patch which disables its Info Center shortcut tool, used in 100 different HP laptop models, in an attempt to work around a design flaw.

HP has labelled the flaw "critical". It affects 15 variations of HP's Compaq Presario Notebook PC series, three in the HP 500 Notebook model series, 46 in the HP Compaq Notebook PC series, and 14 in the HP Pavilion Notebook PC series, as well as other models, according to HP's security notice.

News of the flaw was reported by a researcher using the name "porkythepig" on the Bugtraq security bulletin on 11 December. The researcher discovered that flaws in HPInfoDLL.dll — one of the ActiveX controls used within HP Info Center — could allow remote attackers to carry out a number of malicious activities.

These include installing malware, changing registry information in preparation for a more sophisticated attack, using the machine in a denial-of-service attack and stealing sensitive data from documents on the compromised machine.

For the flaw to be exploited, the user of an affected laptop would need to visit a specially crafted website.

Exploit code has been posted on vulnerability-alert site milw0rm and on SecurityFocus's Bugtraq.

CNET News.com's Robert Vamosi and ZDNet.co.uk's Tom Espiner contributed to this article.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
18 out of 21 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

S48892: SAP Specialist - 3rd Line Support

Manage and support Physical Servers (HP/Compaq servers) for SAP systems. SAP Specialist - 3rd Line Support Warwick up to 40,000 plus on call ...

Commissioning Engineers - TREND - 35k + Car + Benefits

Benefits include excellent base salary, company car/allowance, mobile phone, pension & laptop. The nature of the role will be to carry out the ...

MS Senior Support Analyst 25-30k Warrington

Other elements that will support their application will include experience with HP compaq & Dell Laptops, MS office, Adobe reader, blackberries & 3G ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation