SCO OpenServer lp Buffer Overflow Vulnerability
BID:2589
Info
SCO OpenServer lp Buffer Overflow Vulnerability
| Bugtraq ID: | 2589 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 13 2001 12:00AM |
| Updated: | Apr 13 2001 12:00AM |
| Credit: | Most of the vulnerabilities in the initial SCO advisory addressing this issue were discovered by Kevin Finisterre <[email protected]>. Reported to bugtraq by Albert Fu <[email protected]> in a security advisory dated Thu, 12 Apr 2001. |
| Vulnerable: |
SCO Open Server 5.0.6 SCO Open Server 5.0.5 SCO Open Server 5.0.4 SCO Open Server 5.0.3 SCO Open Server 5.0.2 SCO Open Server 5.0.1 SCO Open Server 5.0 |
| Not Vulnerable: | |
Discussion
SCO OpenServer lp Buffer Overflow Vulnerability
SCO OpenServer 5 ships with several suid 'bin' executables used in printer administration and related tasks.
This includes lp, a component used to submit files and relevant information for printing.
'lp' contains a confirmed locally exploitable buffer overflow condition present in the handling of command-line parameters.
If properly exploited, this can yield user 'bin' privileges to the attacker.
SCO OpenServer 5 ships with several suid 'bin' executables used in printer administration and related tasks.
This includes lp, a component used to submit files and relevant information for printing.
'lp' contains a confirmed locally exploitable buffer overflow condition present in the handling of command-line parameters.
If properly exploited, this can yield user 'bin' privileges to the attacker.
References
SCO OpenServer lp Buffer Overflow Vulnerability
References:
References: