CVE-2009-0122
Estado: ModificadaMedia (6.9)—
hplip.postinst in HP Linux Imaging and Printing (HPLIP) 2.7.7 and 2.8.2 on Ubuntu allows local users to change the ownership of arbitrary files via unspecified manipulations in advance of an HPLIP installation or upgrade by an administrator, related to the product's attempt to correct the ownership of its configuration files within home directories.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 6.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.51%
- Percentil entre todas las CVEs puntuadas: 41
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2009-0122",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.9,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": true,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-01-15T17:30:00.483",
"references": [
{
"url": "http://secunia.com/advisories/33539",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/33249",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.ubuntu.com/usn/usn-708-1",
"source": "cve@mitre.org"
},
{
"url": "https://launchpad.net/bugs/191299",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/33539",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/33249",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/usn-708-1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://launchpad.net/bugs/191299",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "hplip.postinst in HP Linux Imaging and Printing (HPLIP) 2.7.7 and 2.8.2 on Ubuntu allows local users to change the ownership of arbitrary files via unspecified manipulations in advance of an HPLIP installation or upgrade by an administrator, related to the product's attempt to correct the ownership of its configuration files within home directories."
},
{
"lang": "es",
"value": "hplip.postinst en HP Linux Imaging and Printing (HPLIP) v2.7.7 y v2.8.2 en Ubuntu permite a usuarios locales cambiar la propiedad de ficheros a su elección a través de manipulaciones inespecificadas de manera previa a la instalación o mejora del HPLIP por parte del administrador, relacionado con los intentos de corrección de propietario en sus ficheros de configuración en los directorios locales."
}
],
"lastModified": "2026-06-16T23:04:17.983",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hp:hplip:2.7.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ED2C0484-7995-488C-BF9D-61A4EC318F92"
},
{
"criteria": "cpe:2.3:a:hp:hplip:2.8.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "205AA0F1-796F-49EA-933F-245B558F4C3B"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "Not vulnerable. This issue did not affect the versions of hplip as shipped with Red Hat Enterprise Linux 5.\n",
"lastModified": "2009-01-19T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cve@mitre.org"
}