Easy Software Products LPPassWd Resource Limit Denial Of Service Vulnerability
BID:12005
Info
Easy Software Products LPPassWd Resource Limit Denial Of Service Vulnerability
| Bugtraq ID: | 12005 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-1269 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Jul 12 2009 09:26AM |
| Credit: | Discovery is credited to Bartlomiej Sieka. |
| Vulnerable: |
SGI ProPack 3.0 Redhat Linux 9.0 i386 Redhat Linux 7.3 i386 Redhat Fedora Core1 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 3 Redhat Desktop 3.0 Easy Software Products lppasswd 1.1.22 |
| Not Vulnerable: | |
Discussion
Easy Software Products LPPassWd Resource Limit Denial Of Service Vulnerability
Easy Software Products lppasswd is prone to a locally exploitable denial of service vulnerability. This issue occurs when the program attempts to write a file to the system that will exceed any file size resource limits in place. This presents a vulnerability since an unprivileged user with CUPS credentials may set these resource limits and then invoke the application. This will create an empty '/usr/local/etc/cups/passwd.new' file. If this file is present, then future invocations of lppasswd will fail.
Successful exploitation will prevent users from changing their CUPS passwords with lppasswd.
Easy Software Products lppasswd is prone to a locally exploitable denial of service vulnerability. This issue occurs when the program attempts to write a file to the system that will exceed any file size resource limits in place. This presents a vulnerability since an unprivileged user with CUPS credentials may set these resource limits and then invoke the application. This will create an empty '/usr/local/etc/cups/passwd.new' file. If this file is present, then future invocations of lppasswd will fail.
Successful exploitation will prevent users from changing their CUPS passwords with lppasswd.
Exploit / POC
Easy Software Products LPPassWd Resource Limit Denial Of Service Vulnerability
The following exploit was published:
The following exploit was published:
Solution / Fix
Easy Software Products LPPassWd Resource Limit Denial Of Service Vulnerability
Solution:
Red Hat has released an advisory (RHSA-2005:013-20) to address various issues in CUPS. Please see the advisory in Web references for more information.
Mandrake has released advisory MDKSA-2005:008 to address various issues related to CUPS. Please see the referenced advisory for more information.
SGI has released advisory 20050101-01-U (SGI Advanced Linux Environment 3 Security Update #23) to address various issues in SGI Advanced Linux Environment 3. This advisory includes updated SGI ProPack 3 Service Pack 3 packages and patch 10137. Please see the referenced advisory for more information.
TurboLinux has released Security Announcement 17/Feb/2005 dealing with this and other issues; please see the reference section for more information.
Fedora has released Fedora Legacy Advisory (FLSA:2127) to address various issues affecting CUPS in Red Hat Linux 7.3, Red Hat Linux 9, and Fedora Core 1 for the i386 architecture. Please see the referenced advisory for more information.
SGI ProPack 3.0
Solution:
Red Hat has released an advisory (RHSA-2005:013-20) to address various issues in CUPS. Please see the advisory in Web references for more information.
Mandrake has released advisory MDKSA-2005:008 to address various issues related to CUPS. Please see the referenced advisory for more information.
SGI has released advisory 20050101-01-U (SGI Advanced Linux Environment 3 Security Update #23) to address various issues in SGI Advanced Linux Environment 3. This advisory includes updated SGI ProPack 3 Service Pack 3 packages and patch 10137. Please see the referenced advisory for more information.
TurboLinux has released Security Announcement 17/Feb/2005 dealing with this and other issues; please see the reference section for more information.
Fedora has released Fedora Legacy Advisory (FLSA:2127) to address various issues affecting CUPS in Red Hat Linux 7.3, Red Hat Linux 9, and Fedora Core 1 for the i386 architecture. Please see the referenced advisory for more information.
SGI ProPack 3.0
-
SGI patch10137.tar.gz
ftp://patches.sgi.com/support/free/security/patches/ProPack/3/patch101 37.tar.gz
References
Easy Software Products LPPassWd Resource Limit Denial Of Service Vulnerability
References:
References:
- [local] [kill] CUPS 1.1.22 lppasswd ignores write errors, etc. ("D. J. Bernstein"
) - Easy Software Products Homepage (Easy Software Products)
- RHSA-2005:013-20 - CUPS (RedHat)