Multiple flaws found in HP Software Update tool

By Liam Tung, ZDNet Australia
Tuesday, April 29, 2008 11:58 AM

HP’s Software Update Tool was found to contain flaws which could lead to remote code execution or the leakage of sensitive information stored on a PC.

The offending component of the HP Software Update application is the HPeDiag ActiveX control, which checks for and downloads security, firmware, software and driver updates.

The flaw affects any HP PCs, or any PC connected to HP scanners, printers and cameras that contain a version of the update.

Tan Chew Keong from Vuln.sg, who advised HP of the flaw in March, said the vulnerable ActiveX controls were installed as part of HP Software Update version 3.0.2.991 when the user installs the Windows software suite for HP colour LaserJet 2820/2840.

However, according to HP's security advisory, the flaw affects a larger set of products, including scanners, printers, cameras and PCs that use HP Software Update. Updates v4.000.009.002 or earlier running on Windows may be exposed to the vulnerability but should be resolved for PCs with update v4.000.010.008 or higher.

"A successful exploit requires that the user is tricked into visiting a malicious Web site using IE6 or earlier. If the user uses IE7, he must first be convinced into allowing the ActiveX control to run," Tan said.

HP has not clarified in its advisory which versions of Internet Explorer are vulnerable to such an attack; however, it does explain how to resolve the problem.

HP has not advised customers to disable ActiveX in Internet Explorer, however USCert and Tan recommend doing so.

The flawed application is the second threat that HP has exposed its customers to this month. HP previously shipped malware-infected USB drives for its ProLiant servers.

HP was unable to respond to ZDNet Australia's questions at the time of writing.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Mainsoft: Opening options for Java, .NET developers

Java

Mainsoft provides tools for running .NET code on the Java platform.


Read more »


Tags

  1. against
  2. antivirus
  3. asian
  4. attacks
  5. blame
  6. by
  7. critical
  8. cyber
  9. data
  10. flaw
  11. flaws
  12. google
  13. govt
  14. hit
  15. hp
  16. malware
  17. microsoft
  18. online
  19. over
  20. security
  21. software
  22. symantec
  23. threats
  24. uk
  25. under
  26. update
  27. updates
  28. us
  29. warns
  30. web
 
Oracle SOA Business Software Centre
Many companies are recognizing the need to adopt standards in their efforts to build service-oriented applications.
Secure the "Next-Gen SOA Infrastructure" & "Bringing SOA Value Patterns to Life" whitepapers here

» Visit the Power Center
Increase performance with eco-technology innovations
Simplify your infrastructure and unify management, while lowering power and cooling costs of your datacenter.
» Maximum flexibility with powerful blade technolgy
» Bring new services and applications online faster
» Lower energy use and cost

Up close and personal with a merger

Blog thumbnail

What can you get for 13.9 billion buckaroos? For Hewlett-Packard, US$13.9 billion would allow you to buy your way into becoming the second biggest IT services company in the industry...... by Eileen Yu

Read more »