Multiple Vendor lpd Remote Buffer Overflow Vulnerability
BID:2894
Info
Multiple Vendor lpd Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 2894 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2001 12:00AM |
| Updated: | Jun 19 2001 12:00AM |
| Credit: | Discovered by X-Force <[email protected]>. |
| Vulnerable: |
Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6 SGI IRIX 6.5.13 m SGI IRIX 6.5.13 f SGI IRIX 6.5.12 m SGI IRIX 6.5.12 f SGI IRIX 6.5.11 m SGI IRIX 6.5.11 f SGI IRIX 6.5.10 m SGI IRIX 6.5.10 f SGI IRIX 6.5.9 m SGI IRIX 6.5.9 f SGI IRIX 6.5.8 m SGI IRIX 6.5.8 f SGI IRIX 6.5.7 m SGI IRIX 6.5.7 f SGI IRIX 6.5.6 m SGI IRIX 6.5.6 f SGI IRIX 6.5.5 m SGI IRIX 6.5.5 f SGI IRIX 6.5.4 m SGI IRIX 6.5.4 f SGI IRIX 6.5.3 m SGI IRIX 6.5.3 f SGI IRIX 6.5.2 m SGI IRIX 6.5.2 f SGI IRIX 6.5.1 SGI IRIX 6.5 NetBSD NetBSD current pre20010805 NetBSD NetBSD 1.5.2 NetBSD NetBSD 1.5.1 NetBSD NetBSD 1.5 x86 NetBSD NetBSD 1.5 sh3 NetBSD NetBSD 1.5 NetBSD NetBSD 1.4.3 NetBSD NetBSD 1.4.2 x86 NetBSD NetBSD 1.4.2 SPARC NetBSD NetBSD 1.4.2 arm32 NetBSD NetBSD 1.4.2 Alpha NetBSD NetBSD 1.4.2 NetBSD NetBSD 1.4.1 x86 NetBSD NetBSD 1.4.1 SPARC NetBSD NetBSD 1.4.1 sh3 NetBSD NetBSD 1.4.1 arm32 NetBSD NetBSD 1.4.1 Alpha NetBSD NetBSD 1.4.1 NetBSD NetBSD 1.4 x86 NetBSD NetBSD 1.4 SPARC NetBSD NetBSD 1.4 arm32 NetBSD NetBSD 1.4 Alpha NetBSD NetBSD 1.4 IBM AIX 4.3 IBM AIX 5.1 |
| Not Vulnerable: | |
Discussion
Multiple Vendor lpd Remote Buffer Overflow Vulnerability
BSD-based line printer daemons such as 'in.lpd' or 'lpd' contain a remotely exploitable buffer overflow vulnerability.
Remote attackers can exploit this vulnerability to execute arbitrary code on the target host. The daemon runs with root privileges.
The daemon is enabled by default on AIX and Solaris systems.
BSD-based line printer daemons such as 'in.lpd' or 'lpd' contain a remotely exploitable buffer overflow vulnerability.
Remote attackers can exploit this vulnerability to execute arbitrary code on the target host. The daemon runs with root privileges.
The daemon is enabled by default on AIX and Solaris systems.
Exploit / POC
Multiple Vendor lpd Remote Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Vendor lpd Remote Buffer Overflow Vulnerability
Solution:
Administrators are strongly advised to either apply network access control to the service or disable 'in.lpd'. The daemon can be disabled by commenting out its associated line in '/etc/inetd.conf' and re-starting inetd.
Patches are available.
Sun Solaris 8_sparc
Sun Solaris 2.6_x86
NetBSD NetBSD current pre20010805
IBM AIX 5.1
Sun Solaris 7.0
Sun Solaris 7.0_x86
Sun Solaris 2.6
Sun Solaris 8_x86
NetBSD NetBSD 1.4 x86
NetBSD NetBSD 1.4 Alpha
NetBSD NetBSD 1.4 SPARC
NetBSD NetBSD 1.4
NetBSD NetBSD 1.4 arm32
NetBSD NetBSD 1.4.1 Alpha
NetBSD NetBSD 1.4.1 arm32
NetBSD NetBSD 1.4.1 x86
NetBSD NetBSD 1.4.1
NetBSD NetBSD 1.4.1 SPARC
NetBSD NetBSD 1.4.1 sh3
NetBSD NetBSD 1.4.2
NetBSD NetBSD 1.4.2 x86
NetBSD NetBSD 1.4.2 arm32
NetBSD NetBSD 1.4.2 Alpha
NetBSD NetBSD 1.4.2 SPARC
NetBSD NetBSD 1.4.3
NetBSD NetBSD 1.5 x86
NetBSD NetBSD 1.5
NetBSD NetBSD 1.5 sh3
NetBSD NetBSD 1.5.1
NetBSD NetBSD 1.5.2
IBM AIX 4.3
SGI IRIX 6.5
SGI IRIX 6.5.1
SGI IRIX 6.5.10 f
SGI IRIX 6.5.10 m
SGI IRIX 6.5.11 m
SGI IRIX 6.5.11 f
SGI IRIX 6.5.12 f
SGI IRIX 6.5.12 m
SGI IRIX 6.5.13 f
SGI IRIX 6.5.13 m
SGI IRIX 6.5.2 m
SGI IRIX 6.5.2 f
SGI IRIX 6.5.3 m
SGI IRIX 6.5.3 f
SGI IRIX 6.5.4 m
SGI IRIX 6.5.4 f
SGI IRIX 6.5.5 m
SGI IRIX 6.5.5 f
SGI IRIX 6.5.6 m
SGI IRIX 6.5.6 f
SGI IRIX 6.5.7 m
SGI IRIX 6.5.7 f
SGI IRIX 6.5.8 m
SGI IRIX 6.5.8 f
SGI IRIX 6.5.9 f
SGI IRIX 6.5.9 m
Solution:
Administrators are strongly advised to either apply network access control to the service or disable 'in.lpd'. The daemon can be disabled by commenting out its associated line in '/etc/inetd.conf' and re-starting inetd.
Patches are available.
Sun Solaris 8_sparc
Sun Solaris 2.6_x86
NetBSD NetBSD current pre20010805
-
NetBSD 1.5.x, current SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
IBM AIX 5.1
Sun Solaris 7.0
Sun Solaris 7.0_x86
Sun Solaris 2.6
Sun Solaris 8_x86
NetBSD NetBSD 1.4 x86
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4 Alpha
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4 SPARC
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4 arm32
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4.1 Alpha
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4.1 arm32
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4.1 x86
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4.1
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4.1 SPARC
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4.1 sh3
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4.2
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4.2 x86
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4.2 arm32
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4.2 Alpha
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4.2 SPARC
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.4.3
-
NetBSD 1.4.x SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.5 x86
-
NetBSD 1.5.x, current SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.5
-
NetBSD 1.5.x, current SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.5 sh3
-
NetBSD 1.5.x, current SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.5.1
-
NetBSD 1.5.x, current SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
NetBSD NetBSD 1.5.2
-
NetBSD 1.5.x, current SA2001-018-lpd.patch
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/SA2001-018-lpd.patch
IBM AIX 4.3
SGI IRIX 6.5
SGI IRIX 6.5.1
SGI IRIX 6.5.10 f
SGI IRIX 6.5.10 m
SGI IRIX 6.5.11 m
SGI IRIX 6.5.11 f
SGI IRIX 6.5.12 f
SGI IRIX 6.5.12 m
SGI IRIX 6.5.13 f
SGI IRIX 6.5.13 m
SGI IRIX 6.5.2 m
SGI IRIX 6.5.2 f
SGI IRIX 6.5.3 m
SGI IRIX 6.5.3 f
SGI IRIX 6.5.4 m
SGI IRIX 6.5.4 f
SGI IRIX 6.5.5 m
SGI IRIX 6.5.5 f
SGI IRIX 6.5.6 m
SGI IRIX 6.5.6 f
SGI IRIX 6.5.7 m
SGI IRIX 6.5.7 f
SGI IRIX 6.5.8 m
SGI IRIX 6.5.8 f
SGI IRIX 6.5.9 f
SGI IRIX 6.5.9 m