The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message. http://securitytracker.com/alerts/2008/Aug/1020684.html
"A local user can send specially crafted packets to cause the alert mailing function to execute arbitrary commands on the target system with root privileges.
Impact: A local user can obtain root privileges on the target system."
Publication date: Fri, 15 Aug 2008 01:41:00 +0000