Multiple BSD Vendor lpd Buffer Overflow Vulnerability
BID:3252
Info
Multiple BSD Vendor lpd Buffer Overflow Vulnerability
| Bugtraq ID: | 3252 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2001 12:00AM |
| Updated: | Aug 29 2001 12:00AM |
| Credit: | Discovered by X-Force <[email protected]>. |
| Vulnerable: |
SuSE Linux 7.2 SuSE Linux 7.1 x86 SuSE Linux 7.1 sparc SuSE Linux 7.1 ppc SuSE Linux 7.1 alpha SuSE Linux 7.0 sparc SuSE Linux 7.0 ppc SuSE Linux 7.0 alpha SuSE Linux 7.0 SuSE Linux 6.4 ppc SuSE Linux 6.4 alpha SuSE Linux 6.4 SuSE Linux 6.3 alpha SuSE Linux 6.3 SCO Open Server 5.0.6 a SCO Open Server 5.0.6 SCO Open Server 5.0.5 SCO Open Server 5.0.4 SCO Open Server 5.0.3 SCO Open Server 5.0.2 SCO Open Server 5.0.1 OpenBSD OpenBSD 2.9 OpenBSD OpenBSD 2.8 OpenBSD OpenBSD 2.7 OpenBSD OpenBSD 2.6 OpenBSD OpenBSD 2.5 OpenBSD OpenBSD 2.4 OpenBSD OpenBSD 2.3 OpenBSD OpenBSD 2.2 OpenBSD OpenBSD 2.1 OpenBSD OpenBSD 2.0 NetBSD NetBSD 1.5.1 NetBSD NetBSD 1.5 NetBSD NetBSD 1.4.3 NetBSD NetBSD 1.4.2 NetBSD NetBSD 1.4.1 NetBSD NetBSD 1.4 NetBSD NetBSD 1.3.3 NetBSD NetBSD 1.3.2 NetBSD NetBSD 1.3.1 NetBSD NetBSD 1.3 NetBSD NetBSD 1.2.1 NetBSD NetBSD 1.2 NetBSD NetBSD 1.1 NetBSD NetBSD 1.0 FreeBSD FreeBSD 4.2 FreeBSD FreeBSD 4.1.1 FreeBSD FreeBSD 4.1 FreeBSD FreeBSD 4.0 FreeBSD FreeBSD 3.5.1 FreeBSD FreeBSD 3.5 FreeBSD FreeBSD 3.4 FreeBSD FreeBSD 3.3 FreeBSD FreeBSD 3.2 FreeBSD FreeBSD 3.1 FreeBSD FreeBSD 3.0 FreeBSD FreeBSD 2.2.8 FreeBSD FreeBSD 2.2.6 FreeBSD FreeBSD 2.2.5 FreeBSD FreeBSD 2.2.4 FreeBSD FreeBSD 2.2.3 FreeBSD FreeBSD 2.2.2 FreeBSD FreeBSD 2.2 BSDI BSD/OS 4.1 BSDI BSD/OS 4.0.1 BSDI BSD/OS 4.0 BSDI BSD/OS 3.1 BSDI BSD/OS 3.0 BSDI BSD/OS 2.0.1 BSDI BSD/OS 2.0 |
| Not Vulnerable: |
BSDI BSD/OS 4.2 |
Discussion
Multiple BSD Vendor lpd Buffer Overflow Vulnerability
The BSD print protocol daemon, shipped with many systems, contains a remotely exploitable buffer overflow vulnerability. The daemon listens on TCP port 515 and facilitates printing over a network. It is often enabled by default.
The printer daemon must be properly configured to exploit this vulnerability. Some systems do not ship with the service enabled, such as OpenBSD and FreeBSD. On systems where the daemon is enabled, the attack must be launched from a host in the '/etc/hosts.equiv' or '/etc/hosts.lpd' files.
If exploited, remote attackers may be able to gain superuser access to vulnerable systems.
The BSD print protocol daemon, shipped with many systems, contains a remotely exploitable buffer overflow vulnerability. The daemon listens on TCP port 515 and facilitates printing over a network. It is often enabled by default.
The printer daemon must be properly configured to exploit this vulnerability. Some systems do not ship with the service enabled, such as OpenBSD and FreeBSD. On systems where the daemon is enabled, the attack must be launched from a host in the '/etc/hosts.equiv' or '/etc/hosts.lpd' files.
If exploited, remote attackers may be able to gain superuser access to vulnerable systems.
Exploit / POC
Multiple BSD Vendor lpd Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple BSD Vendor lpd Buffer Overflow Vulnerability
Solution:
WindRiver has released a fix for BSD/OS version 4.1.
Patches will be available from other affected vendors soon.
Security Focus recommends disabling the service or blocking outside access to it immediately. This may be accomplished by terminating the processes/disabling the service on the affected hosts or implementing strict network access controls limiting access to the service.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
FreeBSD FreeBSD 3.0
FreeBSD FreeBSD 3.1
FreeBSD FreeBSD 3.2
FreeBSD FreeBSD 3.3
FreeBSD FreeBSD 3.4
FreeBSD FreeBSD 3.5
FreeBSD FreeBSD 3.5.1
FreeBSD FreeBSD 4.0
BSDI BSD/OS 4.1
FreeBSD FreeBSD 4.1
FreeBSD FreeBSD 4.1.1
FreeBSD FreeBSD 4.2
SCO Open Server 5.0.1
SCO Open Server 5.0.2
SCO Open Server 5.0.3
SCO Open Server 5.0.4
SCO Open Server 5.0.5
SCO Open Server 5.0.6 a
SCO Open Server 5.0.6
SuSE Linux 6.3
SuSE Linux 6.3 alpha
SuSE Linux 6.4 ppc
SuSE Linux 6.4 alpha
SuSE Linux 6.4
SuSE Linux 7.0 ppc
SuSE Linux 7.0
SuSE Linux 7.0 sparc
SuSE Linux 7.0 alpha
SuSE Linux 7.1 x86
SuSE Linux 7.1 sparc
SuSE Linux 7.1 ppc
SuSE Linux 7.1 alpha
SuSE Linux 7.2
Solution:
WindRiver has released a fix for BSD/OS version 4.1.
Patches will be available from other affected vendors soon.
Security Focus recommends disabling the service or blocking outside access to it immediately. This may be accomplished by terminating the processes/disabling the service on the affected hosts or implementing strict network access controls limiting access to the service.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
FreeBSD FreeBSD 3.0
-
FreeBSD 3.x-4.2 lpd-3.x-4.2.patch
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/patches/SA-01:58/lpd-3.x-4.2.pa tch
FreeBSD FreeBSD 3.1
-
FreeBSD 3.x-4.2 lpd-3.x-4.2.patch
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/patches/SA-01:58/lpd-3.x-4.2.pa tch
FreeBSD FreeBSD 3.2
-
FreeBSD 3.x-4.2 lpd-3.x-4.2.patch
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/patches/SA-01:58/lpd-3.x-4.2.pa tch
FreeBSD FreeBSD 3.3
-
FreeBSD 3.x-4.2 lpd-3.x-4.2.patch
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/patches/SA-01:58/lpd-3.x-4.2.pa tch
FreeBSD FreeBSD 3.4
-
FreeBSD 3.x-4.2 lpd-3.x-4.2.patch
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/patches/SA-01:58/lpd-3.x-4.2.pa tch
FreeBSD FreeBSD 3.5
-
FreeBSD 3.x-4.2 lpd-3.x-4.2.patch
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/patches/SA-01:58/lpd-3.x-4.2.pa tch
FreeBSD FreeBSD 3.5.1
-
FreeBSD 3.x-4.2 lpd-3.x-4.2.patch
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/patches/SA-01:58/lpd-3.x-4.2.pa tch
FreeBSD FreeBSD 4.0
-
FreeBSD 3.x-4.2 lpd-3.x-4.2.patch
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/patches/SA-01:58/lpd-3.x-4.2.pa tch
BSDI BSD/OS 4.1
-
BSDI 4.1 M410-044
http://www.BSDI.COM/services/support/patches/patches-4.1/M410-044
FreeBSD FreeBSD 4.1
-
FreeBSD 3.x-4.2 lpd-3.x-4.2.patch
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/patches/SA-01:58/lpd-3.x-4.2.pa tch
FreeBSD FreeBSD 4.1.1
-
FreeBSD 3.x-4.2 lpd-3.x-4.2.patch
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/patches/SA-01:58/lpd-3.x-4.2.pa tch
FreeBSD FreeBSD 4.2
-
FreeBSD 3.x-4.2 lpd-3.x-4.2.patch
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/patches/SA-01:58/lpd-3.x-4.2.pa tch
SCO Open Server 5.0.1
-
Caldera Open Server 5 lpd.tar.Z
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.20/lpd.t ar.Z
SCO Open Server 5.0.2
-
Caldera Open Server 5 lpd.tar.Z
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.20/lpd.t ar.Z
SCO Open Server 5.0.3
-
Caldera Open Server 5 lpd.tar.Z
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.20/lpd.t ar.Z
SCO Open Server 5.0.4
-
Caldera Open Server 5 lpd.tar.Z
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.20/lpd.t ar.Z
SCO Open Server 5.0.5
-
Caldera Open Server 5 lpd.tar.Z
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.20/lpd.t ar.Z
SCO Open Server 5.0.6 a
-
Caldera Open Server 5 lpd.tar.Z
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.20/lpd.t ar.Z
SCO Open Server 5.0.6
-
Caldera Open Server 5 lpd.tar.Z
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.20/lpd.t ar.Z
SuSE Linux 6.3
-
S.u.S.E. 6.3 i386 lprold-3.0.48-275.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/6.3/n1/lprold-3.0.48-275.i386. rpm
SuSE Linux 6.3 alpha
-
S.u.S.E. 6.3 alpha lprold-3.0.48-215.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/6.3/n1/lprold-3.0.48-215.alpha. rpm
SuSE Linux 6.4 ppc
-
S.u.S.E. 6.4 ppc lprold-3.0.48-200.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/n1/lprold-3.0.48-200.ppc.rp m
SuSE Linux 6.4 alpha
-
S.u.S.E. 6.4 alpha lprold-3.0.48-215.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/6.4/n1/lprold-3.0.48-215.alpha. rpm
SuSE Linux 6.4
-
S.u.S.E. 6.4 i386 lprold-3.0.48-275.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/6.4/n1/lprold-3.0.48-275.i386. rpm
SuSE Linux 7.0 ppc
-
S.u.S.E. 7.0 ppc lprold-3.0.48-200.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/n1/lprold-3.0.48-200.ppc.rp m
SuSE Linux 7.0
-
S.u.S.E. 7.0 i386 lprold-3.0.48-275.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.0/n1/lprold-3.0.48-275.i386. rpm
SuSE Linux 7.0 sparc
-
S.u.S.E. 7.0 sparc lprold-3.0.48-216.sparc.rpm
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/n1/lprold-3.0.48-216.spar c.rpm
SuSE Linux 7.0 alpha
-
S.u.S.E. 6.4 alpha lprold-3.0.48-215.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/6.4/n1/lprold-3.0.48-215.alpha. rpm -
S.u.S.E. 7.0 alpha lprold-3.0.48-215.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.0/n1/lprold-3.0.48-215.alpha. rpm
SuSE Linux 7.1 x86
-
S.u.S.E. 7.1 i386 lprold-3.0.48-275.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/n1/lprold-3.0.48-275.i386. rpm
SuSE Linux 7.1 sparc
-
S.u.S.E. 7.1 sparc lprold-3.0.48-216.sparc.rpm
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/n1/lprold-3.0.48-216.spar c.rpm
SuSE Linux 7.1 ppc
-
S.u.S.E. 7.1 ppc lprold-3.0.48-200.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/n1/lprold-3.0.48-200.ppc.rp m
SuSE Linux 7.1 alpha
-
S.u.S.E. 7.1 alpha lprold-3.0.48-215.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.1/n1/lprold-3.0.48-215.alpha. rpm
SuSE Linux 7.2
-
S.u.S.E. 7.2 i386 lprold-3.0.48-272.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n1/lprold-3.0.48-272.i386. rpm
References
Multiple BSD Vendor lpd Buffer Overflow Vulnerability
References:
References:
- BSDI Customer Support Services (BSDI)
- FreeBSD Security Information (FreeBSD)
- NetBSD Security Page (NetBSD)
- OpenBSD Security Information (OpenBSD)