← Vulnerability feed

Vulnerability record · CVE-2007-5208 · published 13 October 2007

CVE-2007-5208: HP hplip hpssd command injection via sendmail from address

Hp · Linux Imaging And Printing Project

hpssd in Hewlett-Packard's Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 fails to validate shell metacharacters in a from address before invoking sendmail. Because that input reaches a shell command, an attacker can inject and execute arbitrary commands. The flaw is remotely reachable and rated High (CVSS 2.0 7.6), so it matters for any host running an unpatched hplip daemon.

7.6 CVSS 2.0 High EPSS 67% · top 0.7% CWE-20 · Improper input validation
7.6CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
48References
16 Jun 2026Last modified by NVD

Description

hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a from address, which is not properly handled when invoking sendmail.

AV:N/AC:H/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityNetwork-reachable, unauthenticated command execution with full impact, offset by high attack complexity and the absence of KEV listing or known exploit tags.

What it is

hpssd in Hewlett-Packard's Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 fails to validate shell metacharacters in a from address before invoking sendmail. Because that input reaches a shell command, an attacker can inject and execute arbitrary commands. The flaw is remotely reachable and rated High (CVSS 2.0 7.6), so it matters for any host running an unpatched hplip daemon.

Impact

An attacker can execute arbitrary commands with the privileges of the hpssd process, giving full compromise of confidentiality, integrity and availability on the affected host.

Attack surface

The vector is network-reachable (AV:N) with no authentication required (Au:N), but exploitation complexity is High (AC:H), meaning the attacker must satisfy context-dependent conditions to deliver the malicious from address. No user interaction is indicated by the record.

Exploitation

CVE-2007-5208 is not listed in CISA KEV and no ransomware groups are documented using it, but EPSS is 0.67264 (99.3rd percentile), indicating a high modeled likelihood of exploitation activity. Reference tags show only a Red Hat Patch/Vendor Advisory, with no public exploit tag.

What to do

  • Upgrade hplip to 2.7.10 or later, or apply the vendor patch referenced in RHSA-2007-0960 and the distribution advisories (Debian DSA-1462, Ubuntu USN-530-1, Gentoo GLSA-200710-26).
  • If patching is not immediately possible, stop or disable the hpssd service and restrict network access to its port to trusted hosts only.
  • Run hpssd with least privilege and avoid running it as root where the platform allows.
  • Audit sendmail invocation paths in hplip for other unvalidated input and sanitize shell metacharacters before command execution.
  • Track the distribution-specific errata for your OS to confirm the fixed package version is installed.

Detection

  • Monitor hpssd process activity for unexpected child processes, especially sendmail or shell invocations with unusual arguments.
  • Search host and mail logs for sendmail invocations containing shell metacharacters (;, |, $(), backticks) in from addresses.
  • Alert on network connections to the hpssd service from untrusted or unexpected hosts.
  • Verify installed hplip package versions against the fixed 2.7.10 baseline and flag older versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.gentoo.org/show_bug.cgi?id=195565
http://lists.opensuse.org/opensuse-security-announce/2007-10/msg00006.html
http://qa.mandriva.com/show_bug.cgi?id=30719
http://secunia.com/advisories/27202
http://secunia.com/advisories/27221
http://secunia.com/advisories/27224
http://secunia.com/advisories/27232
http://secunia.com/advisories/27271
http://secunia.com/advisories/27332
http://secunia.com/advisories/27397
http://secunia.com/advisories/28453
http://security.gentoo.org/glsa/glsa-200710-26.xml
http://www.debian.org/security/2008/dsa-1462
http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:201
http://www.redhat.com/support/errata/RHSA-2007-0960.html PatchVendor Advisory
http://www.securityfocus.com/bid/26054
http://www.securitytracker.com/id?1018806
http://www.vupen.com/english/advisories/2007/3479
https://bugzilla.redhat.com/show_bug.cgi?id=319921
https://exchange.xforce.ibmcloud.com/vulnerabilities/37183
https://launchpad.net/bugs/149121
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10692
https://usn.ubuntu.com/530-1/
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00200.html
http://bugs.gentoo.org/show_bug.cgi?id=195565
http://lists.opensuse.org/opensuse-security-announce/2007-10/msg00006.html
http://qa.mandriva.com/show_bug.cgi?id=30719
http://secunia.com/advisories/27202
http://secunia.com/advisories/27221
http://secunia.com/advisories/27224
http://secunia.com/advisories/27232
http://secunia.com/advisories/27271
http://secunia.com/advisories/27332
http://secunia.com/advisories/27397
http://secunia.com/advisories/28453
http://security.gentoo.org/glsa/glsa-200710-26.xml
http://www.debian.org/security/2008/dsa-1462
http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:201
http://www.redhat.com/support/errata/RHSA-2007-0960.html PatchVendor Advisory
http://www.securityfocus.com/bid/26054

Track CVE-2007-5208 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2010-4267Hp linux imaging and printing project memory buffer overflow vulnerabilityStack-based buffer overflow in the hpmud_get_pml function in io/hpmud/pml.c in Hewlett-Packard Linux Imaging and Printing (HPLIP) 1.6.7, 3.9.8, 3.10.…EPSS 11%7.2CVE-2008-2940Hp linux imaging and printing project permissions and access controls vulnerabilityThe alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from t…EPSS 0.43%6.9CVE-2013-4325Hp linux imaging and printing project permissions and access controls vulnerabilityThe check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communicatio…EPSS 0.42%6.8CVE-2013-6427Hp linux imaging and printing project code injection vulnerabilityupgrade.py in the hp-upgrade service in HP Linux Imaging and Printing (HPLIP) 3.x through 3.13.11 launches a program from an http URL, which allows m…EPSS 4.0%6.8CVE-2011-2697Hp linux imaging and printing project improper input validation vulnerabilityfoomatic-rip-hplip in HP Linux Imaging and Printing (HPLIP) 3.11.5 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPComman…EPSS 11%4.9CVE-2008-2941Hp linux imaging and printing project improper input validation vulnerabilityThe hpssd message parser in hpssd.py in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to cause a denial of service (process stop) vi…EPSS 0.54%2.1CVE-2012-6108Hp linux imaging and printing project permissions and access controls vulnerabilityHP Linux Imaging and Printing (HPLIP) before 3.13.2 uses world-writable permissions for /var/log/hp and /var/log/hp/tmp, which allows local users to …EPSS 0.53%2.1CVE-2013-6402Hp linux imaging and printing project link following vulnerabilitybase/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.11 allows local users to overwrite arbitrary files via a symlink attack on the /tm…EPSS 0.49%

Source: NIST National Vulnerability Database (record CVE-2007-5208), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.