HP warns of LaserJet software flaw

HP has warned that the software supplied with two of its LaserJet business printers could leave PCs open to attack by hackers.

  • E-Mail
By  Matthew Wade Published  April 6, 2006

HP has warned that the software supplied with two of its LaserJet business printers could leave PCs open to attack by hackers. According to the firm’s vulnerability advisory - on the Tech Support section of its global website the problem lies in its ‘Toolbox’ software for Microsoft Windows. The troublesome versions of this Toolbox program are those that were shipped with HP’s 2500 and 4600 colour laser machines, the first of which HP Middle East's website states is still on sale across the Middle East (both models have in fact now been discontinued). The ‘Vulnerability Summary’ in question on HP’s website reads: “A potential security vulnerability has been identified in the HP Color LaserJet 2500 and 4600 Toolbox, which may allow an unauthorized remote attacker to read arbitrary files.” HP then goes on to thank Richard Horsman of Sec-1.com for reporting this vulnerability to security-alert@hp.com. As a result, users of HP’s LaserJet 2500 and 4600 machines should safeguard their computers by installing the relevant Toolbox software updates, which HP has made available for download. LaserJet 2500 owners should go to www.hp.com/go/clj2500_software, select ‘Download Drivers and Software’, then choose the 2500 from the product list and the OS version they are using, before downloading the ‘HP Color LaserJet 2500/4600 Software Update’ version 3.1. 4600 owners should visit www.hp.com/go/clj4600_software and then do the same. HP’s Toolbox software is installed onto a user’s PC at the same time as HP’s LaserJet drivers. The application uses a web browser type of user interface through which owners can access printer status information and view troubleshooting tips.

Add a Comment

Your display name This field is mandatory

Your e-mail address This field is mandatory (Your e-mail address won't be published)

Security code