Enrico Zini discovered that HPLIP used a short GPG key ID when downloading keys from the keyserver. An attacker could possibly use this to return a different key with a duplicate short key id and perform a machine-in-the-middle attack on printer plugin installations.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "hpijs-ppds" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "hplip" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "hplip-data" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "hplip-dbg" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "hplip-dbgsym" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "hplip-doc" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "hplip-gui" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "libhpmud-dev" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "libhpmud-dev-dbgsym" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "libhpmud0" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "libhpmud0-dbgsym" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "libsane-hpaio" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "libsane-hpaio-dbgsym" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "printer-driver-hpcups" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "printer-driver-hpcups-dbgsym" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "printer-driver-hpijs" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "printer-driver-hpijs-dbgsym" }, { "binary_version": "3.14.3-0ubuntu3.4", "binary_name": "printer-driver-postscript-hp" } ] }