April 5, 2006 5:13 PM PDT
HP warns of printer software risks
- Related Stories
-
Second unofficial fix plugs IE hole
March 28, 2006 -
HP colors its business printers
October 17, 2005 -
HP sees speedy advance in MFP printers
June 16, 2005
The vulnerability lies in the Toolbox software that comes with HP's Color LaserJet 2500 and 4600 printers, the company said. The flaw could allow a remote, unauthorized malicious user to retrieve arbitrary files from a Windows computer when the software is running in the default configuration, HP said in a security alert published Sunday.
The Toolbox is software that installs on a PC along with the drivers. It uses a simple Web browser interface for access to printer status information, troubleshooting tips and demos, and an alerts feature.
HP has made HP Color LaserJet 2500/4600 Software Update version 3.1 available to resolve the security issue, it said. Security monitoring company Secunia rates the issue "less critical." The flaw is caused by an input validation error in the Web server that's part of the software, according to a Secunia alert, published Wednesday.
Discovery of the flaw is credited by HP and Secunia to Richard Horsman of Sec-1.com.
See more CNET content tagged:
flaw, printer, HP, security, Microsoft Corp.
6 comments
Join the conversation! Add your comment (Log in or register)
Well a SERVER is meant to SERVE files to someone or something. In
the case of HP there use of a WEB SERVER allows them to create a
WEB INTERFACE for there printers. Thats all fine and dandy but HP,
you should warn your clients of the security risks of running ANY
SERVER on a local machine. Oh, wait, you found ONE flaw, there's
many more, I know this for a fact!
~Justing
Well a SERVER is meant to SERVE files to someone or something. In
the case of HP there use of a WEB SERVER allows them to create a
WEB INTERFACE for there printers. Thats all fine and dandy but HP,
you should warn your clients of the security risks of running ANY
SERVER on a local machine. Oh, wait, you found ONE flaw, there's
many more, I know this for a fact!
~Justing
Bring back a simple set of printer drivers please!
Bring back a simple set of printer drivers please!