Mandriva Linux Security Advisory 2014-023 - It was discovered that the HPLIP Polkit daemon incorrectly handled temporary files. A local attacker could possibly use this issue to overwrite arbitrary files. It was discovered that HPLIP contained an upgrade tool that would download code in an unsafe fashion. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to execute arbitrary code.
91e13eb8f7923827c581c119376fd7f9a940365f7e3775d6636dfeb8210cd760
Ubuntu Security Notice 2085-1 - It was discovered that the HPLIP Polkit daemon incorrectly handled temporary files. A local attacker could possibly use this issue to overwrite arbitrary files. In the default installation of Ubuntu 12.04 LTS and higher, this should be prevented by the Yama link restrictions. It was discovered that HPLIP contained an upgrade tool that would download code in an unsafe fashion. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to execute arbitrary code. Various other issues were also addressed.
82c9a363a9042992362ccff7d326ebeec0884d0c91fb82f0fb606370bad9f552
Debian Linux Security Advisory 2829-1 - Multiple vulnerabilities have been found in the HP Linux Printing and in PackageKit and the insecure hp-upgrade service has been disabled.
7f66cf46f3fd1529cdf09546ae8258fcde1c2abdabfa3412509c82a4b988c067
Slackware Security Advisory - New hplip packages are available for Slackware 14.0 to fix a security issue. Related CVE Numbers: CVE-2013-6427.
1ba04e10c0d66ced8dbd752ad260d572674eb59da2d34d66cce1d2c3a7ef5734