Home > Security News > HP customers vulnerable to software update tool flaw
Security News:
EMAIL THIS

HP customers vulnerable to software update tool flaw

By SearchSecurity.com Staff
29 Apr 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

A dangerous flaw in Hewlett-Packard Software Update, a tool that automatically updates HP software and drivers, could be exploited by an attacker to read sensitive information or gain access to a system.

Successful exploit requires that the user is tricked into visiting a malicious website using IE6 or earlier.
Tan Chew Keong.
security researcher

The tools contain several ActiveX flaws that could be exploited by tricking Internet Explorer users into visiting a malicious website.

Danish vulnerability clearinghouse Secunia gave the threat a "highly critical" rating in its Secunia SA29966 advisory. Secunia said the potential exposure of system and other sensitive information as well as remote system access warranted the rating.

The vulnerabilities are reported in versions 4.000.009.002 and prior. HP has issued an advisory and an update for the tool to plug the holes. HP said the Software Update tool is often installed as part of software supplied with its PCs, printers, scanners or cameras.

The flaws were discovered by security researcher, Tan Chew Keong. Specifically, the tool has an ActiveX control flaw, which could be exploited by an attacker to cause a stack-based buffer overflow. Keong said the flaws were discovered in March.

"Successful exploit requires that the user is tricked into visiting a malicious website using IE6 or earlier," Keong said in a vuln.sg research advisory. "If the user uses IE7, he must first be convinced into allowing the ActiveX control to run."

A second ActiveX flaw could be exploited to read registry entries or text files. After successfully exploiting the flaw, an attacker could also retrieve system and OS information, Secunia said.



Tags: Application Attacks (Buffer Overflows, Cross-Site Scripting)VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Application Attacks (Buffer Overflows, Cross-Site Scripting)
Adobe ColdFusion websites being compromised
PCI management: The case for Web application firewalls
Month of Twitter Bugs project to document Twitter flaws
Adobe issues first quarterly patch release fixing 13 flaws
Balancing security and performance: Protecting layer 7 on the network
Adobe issues Reader update fixing zero-day flaw
The Pipe Dream of No More Free Bugs
Security Squad: Federal cybersecurity defenses
Oracle issues 43 updates, fixes serious database flaws
Attackers target new Microsoft PowerPoint zero-day flaw
Application Attacks (Buffer Overflows, Cross-Site Scripting) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
buffer overflow  (SearchSecurity.com)
cache poisoning  (SearchSecurity.com)
cyberterrorism  (SearchSecurity.com)
dictionary attack  (SearchSecurity.com)
directory harvest attack  (SearchSecurity.com)
distributed denial-of-service attack  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
ping of death  (SearchSecurity.com)
stack smashing  (SearchSecurity.com)
SYN flooding  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts