SCO OpenServer lpstat Buffer Overflow Vulnerability
BID:2597
Info
SCO OpenServer lpstat Buffer Overflow Vulnerability
| Bugtraq ID: | 2597 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 13 2001 12:00AM |
| Updated: | Apr 13 2001 12:00AM |
| Credit: | Most of the vulnerabilities in the initial SCO advisory addressing this issue were discovered by Kevin Finisterre <[email protected]>. Reported to bugtraq by Albert Fu <[email protected]> in a security advisory dated Thu, 12 Apr 2001. |
| Vulnerable: |
SCO Open Server 5.0.6 SCO Open Server 5.0.5 SCO Open Server 5.0.4 SCO Open Server 5.0.3 SCO Open Server 5.0.2 SCO Open Server 5.0.1 SCO Open Server 5.0 |
| Not Vulnerable: | |
Discussion
SCO OpenServer lpstat Buffer Overflow Vulnerability
SCO OpenServer 5 ships with several suid 'bin' executables used in printer administration and related tasks.
This includes lpstat, a component used to generate a printed report of the status of the lp print service.
'lpstat' contains a confirmed locally exploitable buffer overflow condition present in the handling of command-line parameters.
If properly exploited, this can yield user 'bin' privileges to the attacker.
SCO OpenServer 5 ships with several suid 'bin' executables used in printer administration and related tasks.
This includes lpstat, a component used to generate a printed report of the status of the lp print service.
'lpstat' contains a confirmed locally exploitable buffer overflow condition present in the handling of command-line parameters.
If properly exploited, this can yield user 'bin' privileges to the attacker.
Exploit / POC
SCO OpenServer lpstat Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SCO OpenServer lpstat Buffer Overflow Vulnerability
Solution:
Vendor-supplied fix available:
SCO Open Server 5.0
SCO Open Server 5.0.1
SCO Open Server 5.0.2
SCO Open Server 5.0.3
SCO Open Server 5.0.4
SCO Open Server 5.0.5
SCO Open Server 5.0.6
Solution:
Vendor-supplied fix available:
SCO Open Server 5.0
-
Caldera erg711871.pkg.Z
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.38/erg71 1871.pkg.Z
SCO Open Server 5.0.1
-
Caldera erg711871.pkg.Z
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.38/erg71 1871.pkg.Z
SCO Open Server 5.0.2
-
Caldera erg711871.pkg.Z
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.38/erg71 1871.pkg.Z
SCO Open Server 5.0.3
-
Caldera erg711871.pkg.Z
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.38/erg71 1871.pkg.Z
SCO Open Server 5.0.4
-
Caldera erg711871.pkg.Z
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.38/erg71 1871.pkg.Z
SCO Open Server 5.0.5
-
Caldera erg711871.pkg.Z
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.38/erg71 1871.pkg.Z
SCO Open Server 5.0.6
-
Caldera erg711871.pkg.Z
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.38/erg71 1871.pkg.Z
References
SCO OpenServer lpstat Buffer Overflow Vulnerability
References:
References: