On The Insider: Missed the VS Fashion Show? See the Pix
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Apr 6, 2006 12:13:00 AM

A security flaw in software that ships with two of Hewlett-Packard Color LaserJet printers could open a door for cybersnoops, HP has warned.

The vulnerability lies in the Toolbox software that comes with HP's Color LaserJet 2500 and 4600 printers, the company said. The flaw could allow a remote, unauthorized malicious user to retrieve arbitrary files from a Windows computer when the software is running in the default configuration, HP said in a security alert published Sunday.

The Toolbox is software that installs on a PC along with the drivers. It uses a simple Web browser interface for access to printer status information, troubleshooting tips and demos, and an alerts feature.

HP has made HP Color LaserJet 2500/4600 Software Update version 3.1 available to resolve the security issue, it said. Security monitoring company Secunia rates the issue "less critical." The flaw is caused by an input validation error in the Web server that's part of the software, according to a Secunia alert, published Wednesday.

Discovery of the flaw is credited by HP and Secunia to Richard Horsman of Sec-1.com.

  • Talkback
  • Most Recent of 4 Talkback(s)
HP warns of printer software risks
Although this stance may change soon, HP refuses to admit it, but the same Toolbox software, same "risks" also applies to the HP 2800 series (2840 inclusive) of Color Laser printers as well.

I... (Read the rest)
Posted by: josephrot Posted on: 04/10/06 You are currently: Logged In as: a Guest  | Login | Terms of Use
What??  rpmyers1 | 04/05/06
does this affect the 3500 series? (nt)  wessonjoe | 04/06/06
This would explain the "security update" I got from HP.  Mr. Roboto | 04/06/06
HP warns of printer software risks  josephrot | 04/10/06

What do you think?

advertisement
advertisement
advertisement
Click Here