This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

HP Info Center Software laptop vuln - update available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI… - http://www.us-cert.gov/current/#hp_hp_info_center_software updated December 14, 2007 - "US-CERT is aware of a vulnerability affecting HP Info Center Software, which allows one-touch access to features on HP laptops. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands or to view or alter the system registry on affected systems. These reports also refer to publicly available exploit code for this vulnerability. HP has published an HP Quick Launch Buttons Critical Security Update to address this issue. US-CERT encourages users to apply this update to mitigate this risk. - http://preview.tinyurl.com/2jhrxc (HP Customer Care) Release Date: 2007-12-12 Version: 1.00 A Description: This package provides a critical security update for HP Quick Launch Buttons on the supported notebook models and operating systems. This patch removes a security vulnerability by disabling HP Info Center… » sp38166.exe 1/1 (1.61M) - http://h20000.www2.hp.com/bizsupport/TechS…ectID=c01300486 14 December 2007 - "…HP has provided the following software patch to resolve this vulnerability: HP SoftPaq SP38166… HP suggests that -all- HP notebook PCs have the security patch promptly applied…"
FYI…

HPSBGN02301 SSRT071508 rev.2 - HP Software Update Running on Windows, Remote Execution of Arbitrary Code, Gain Privileged Access
- http://h20000.www2.hp.com/bizsupport/TechS…ectID=c01311918
2 January 2008 (HP Business Support Center) - "Remote execution of arbitrary code, gain privileged access
A potential security vulnerability has been identified with HP Software Update running on Windows. The vulnerability could be exploited remotely to execute arbitrary code or gain privileged access.
> http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6506
Any PC with HP Software Update v4.000.005.007 or earlier running on Windows…
HP has provided two methods to resolve this vulnerability.
1. …HP has provided the following software patch to resolve this vulnerability: HP SoftPaq SP38202. The patch is available for download from ftp://ftp.hp.com/pub/softpaq/sp38001-38500/ .
-Or-
2. Use HP Software Update…"
Version:1 (rev.1) - 21 December 2007 Initial release
Version:2 (rev.2) - 2 January 2008 HP SoftPaq SP38202 available…

> http://secunia.com/advisories/28177

:wall: :ph34r: