HP warns of printer software risks
By Joris Evers
Staff Writer, CNET News.com
Published: April 5, 2006, 5:13 PM PDT
A security flaw in software that
ships with two of Hewlett-Packard Color LaserJet printers could open a door for
cybersnoops, HP has warned.
The vulnerability lies in the
Toolbox software that comes with HP's Color LaserJet 2500 and 4600 printers,
the company said. The flaw could allow a remote, unauthorized malicious user to
retrieve arbitrary files from a Windows computer when the software is running
in the default configuration, HP said in a security alert
published Sunday.
The Toolbox is software that
installs on a PC along with the drivers. It uses a simple Web browser interface
for access to printer status information, troubleshooting tips and demos, and
an alerts feature.
HP has made HP Color LaserJet
2500/4600 Software Update version 3.1 available to resolve the security issue,
it said. Security monitoring company Secunia rates the issue "less
critical." The flaw is caused by an input validation error in the Web server
that's part of the software, according to a Secunia alert,
published Wednesday.
Discovery of the flaw is credited by
HP and Secunia to Richard Horsman of Sec-1.com.