SuSE LPROld Remote File Ownership Changing Vulnerability
BID:3417
Info
SuSE LPROld Remote File Ownership Changing Vulnerability
| Bugtraq ID: | 3417 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2001 12:00AM |
| Updated: | Oct 10 2001 12:00AM |
| Credit: | This vulnerability was discovered by ISS X-Force, and announced via a SuSE Security Advisory on October 10, 2001. |
| Vulnerable: |
SuSE Linux 7.2 SuSE Linux 7.1 x86 SuSE Linux 7.1 sparc SuSE Linux 7.1 ppc SuSE Linux 7.1 alpha SuSE Linux 7.0 sparc SuSE Linux 7.0 ppc SuSE Linux 7.0 alpha SuSE Linux 7.0 SuSE Linux 6.4 ppc SuSE Linux 6.4 alpha SuSE Linux 6.4 SuSE Linux 6.3 alpha SuSE Linux 6.3 |
| Not Vulnerable: | |
Discussion
SuSE LPROld Remote File Ownership Changing Vulnerability
SuSE Linux is a freely available, open source implementation of the Linux Operating System, a UNIX clone. It is maintained and distributed by SuSE.
A problem with the lprold package has been discovered that could allow remote users to gain unauthorized access to system files. This could additionally result in elevated privileges on the local system. It is possible for a remote user to change the ownership on any file on the system. This vulnerability can only be taken advantage of if the system the attack is being launched from is listed in the /etc/hosts.equiv, or /etc/hosts.lpd file.
This could allow a remote user to gain unauthorized access to the system, and potentially elevated privileges.
SuSE Linux is a freely available, open source implementation of the Linux Operating System, a UNIX clone. It is maintained and distributed by SuSE.
A problem with the lprold package has been discovered that could allow remote users to gain unauthorized access to system files. This could additionally result in elevated privileges on the local system. It is possible for a remote user to change the ownership on any file on the system. This vulnerability can only be taken advantage of if the system the attack is being launched from is listed in the /etc/hosts.equiv, or /etc/hosts.lpd file.
This could allow a remote user to gain unauthorized access to the system, and potentially elevated privileges.
Exploit / POC
SuSE LPROld Remote File Ownership Changing Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.