Directory traversal vulnerability in the PostScript Interpreter, as used on the HP LaserJet 4xxx, 5200, 90xx, M30xx, M4345, M50xx, M90xx, P3005, and P4xxx; LaserJet Enterprise P3015; Color LaserJet 3xxx, 47xx, 5550, 9500, CM60xx, CP35xx, CP4005, and CP6015; Color LaserJet Enterprise CP4xxx; and 9250c Digital Sender with model-dependent firmware through 52.x allows remote attackers to read arbitrary files via unknown vectors.

Project Subscriptions

Vendors Products
Color Laserjet 3000 Subscribe
Color Laserjet 3800 Subscribe
Color Laserjet 4700 Subscribe
Color Laserjet 4730 Mfp Subscribe
Color Laserjet 5550 Subscribe
Color Laserjet 9500 Mfp Subscribe
Color Laserjet Cm6030 Mfp Subscribe
Color Laserjet Cm6040 Mfp Subscribe
Color Laserjet Cp3505 Subscribe
Color Laserjet Cp3525 Subscribe
Color Laserjet Cp4005 Subscribe
Color Laserjet Cp6015 Subscribe
Color Laserjet Enterprise Cp4025 Subscribe
Color Laserjet Enterprise Cp4525 Subscribe
Digital Sender 9250c Subscribe
Laserjet 4240 Subscribe
Laserjet 4250 Subscribe
Laserjet 4345 Mfp Subscribe
Laserjet 4350 Subscribe
Laserjet 5200l Subscribe
Laserjet 5200n Subscribe
Laserjet 9040 Subscribe
Laserjet 9040 Mfp Subscribe
Laserjet 9050 Subscribe
Laserjet 9050 Mfp Subscribe
Laserjet Enterprise P3015 Subscribe
Laserjet M3027 Mfp Subscribe
Laserjet M3035 Mfp Subscribe
Laserjet M4345 Mfp Subscribe
Laserjet M5025 Mfp Subscribe
Laserjet M5035 Mfp Subscribe
Laserjet M9040 Mpf Subscribe
Laserjet M9050 Mpf Subscribe
Laserjet P3005 Subscribe
Laserjet P4014 Subscribe
Laserjet P4015 Subscribe
Laserjet P4515 Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2012-5144 Directory traversal vulnerability in the PostScript Interpreter, as used on the HP LaserJet 4xxx, 5200, 90xx, M30xx, M4345, M50xx, M90xx, P3005, and P4xxx; LaserJet Enterprise P3015; Color LaserJet 3xxx, 47xx, 5550, 9500, CM60xx, CP35xx, CP4005, and CP6015; Color LaserJet Enterprise CP4xxx; and 9250c Digital Sender with model-dependent firmware through 52.x allows remote attackers to read arbitrary files via unknown vectors.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2024-08-06T20:58:03.213Z

Reserved: 2012-10-01T00:00:00.000Z

Link: CVE-2012-5221

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-04-29T21:55:00.997

Modified: 2025-04-11T00:51:21.963

Link: CVE-2012-5221

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses