IRIX 'lpsched' Remote Command Execution Vulnerability
BID:27566
Info
IRIX 'lpsched' Remote Command Execution Vulnerability
| Bugtraq ID: | 27566 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0800 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 09 2001 12:00AM |
| Updated: | Feb 04 2008 02:56PM |
| Credit: | Last Stage of Delirium is credited with discovering this issue. |
| Vulnerable: |
SGI IRIX 6.5.13 m SGI IRIX 6.5.13 f SGI IRIX 6.5.12 m SGI IRIX 6.5.12 f SGI IRIX 6.5.11 m SGI IRIX 6.5.11 f SGI IRIX 6.5.10 m SGI IRIX 6.5.10 f SGI IRIX 6.5.9 m SGI IRIX 6.5.9 f SGI IRIX 6.5.8 m SGI IRIX 6.5.8 f SGI IRIX 6.5.7 m SGI IRIX 6.5.7 f SGI IRIX 6.5.6 m SGI IRIX 6.5.6 f SGI IRIX 6.5.5 m SGI IRIX 6.5.5 f SGI IRIX 6.5.4 m SGI IRIX 6.5.4 f SGI IRIX 6.5.3 m SGI IRIX 6.5.3 f SGI IRIX 6.5.2 m SGI IRIX 6.5.2 f SGI IRIX 6.5.1 SGI IRIX 6.5 |
| Not Vulnerable: |
SGI IRIX 6.5.14 m SGI IRIX 6.5.14 f |
Discussion
IRIX 'lpsched' Remote Command Execution Vulnerability
The 'lpsched' utility in IRIX is prone to a remote shell command-execution vulnerability.
Successfully exploiting this issue can allow arbitrary commands to run in the context of the affected user.
The 'lpsched' utility in IRIX is prone to a remote shell command-execution vulnerability.
Successfully exploiting this issue can allow arbitrary commands to run in the context of the affected user.
Exploit / POC
IRIX 'lpsched' Remote Command Execution Vulnerability
To exploit this issue, attackers can use readily available networking utilities.
The following exploit code is available as a module for the Metasploit Framework:
To exploit this issue, attackers can use readily available networking utilities.
The following exploit code is available as a module for the Metasploit Framework:
Solution / Fix
IRIX 'lpsched' Remote Command Execution Vulnerability
Solution:
Please see the references for more information.
Solution:
Please see the references for more information.
References
IRIX 'lpsched' Remote Command Execution Vulnerability
References:
References: