IRIX lp Vulnerability
BID:40
Info
IRIX lp Vulnerability
| Bugtraq ID: | 40 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 1992 12:00AM |
| Updated: | Apr 10 1992 12:00AM |
| Credit: | |
| Vulnerable: |
SGI IRIX 4.0.4 B SGI IRIX 4.0.4 SGI IRIX 4.0.3 SGI IRIX 4.0.2 SGI IRIX 4.0.1 SGI IRIX 4.0 SGI IRIX 3.3.3 SGI IRIX 3.3.2 SGI IRIX 3.3.1 SGI IRIX 3.3 SGI IRIX 3.2 |
| Not Vulnerable: |
SGI IRIX 4.0.5 SGI IRIX 4.0.4 T SGI IRIX 4.0.1 T |
Discussion
IRIX lp Vulnerability
When IRIX pre-4.0.5 systems are installed or updated using either
the basic system software ("eoe1.sw.unix") or the system manager
software ("eoe2.sw.vadmin") media, a vulnerability is introduced
in the lp software.
Any user logged into the system can gain root access.
When IRIX pre-4.0.5 systems are installed or updated using either
the basic system software ("eoe1.sw.unix") or the system manager
software ("eoe2.sw.vadmin") media, a vulnerability is introduced
in the lp software.
Any user logged into the system can gain root access.
Exploit / POC
IRIX lp Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IRIX lp Vulnerability
Solution:
As root, execute the following commands:
# cd /usr/lib
# chmod a-s,go-w lpshut lpmove accept reject lpadmin
# chmod go-ws lpsched vadmin/serial_ports vadmin/users vadmin/disks
# cd /usr/bin
# chmod a-s,go-w disable enable
# chmod go-ws cancel lp lpstat
If the eoe2.sw.vadmin software is not installed, you may
ignore any warning messages from chmod such as:
"chmod: WARNING: can't access vadmin/serial_ports"
If system software should ever be reinstalled from pre-4.0.5
media or restored from a backup tape created before the patch was
applied, repeat the above procedure before enabling logins by
normal users.
Solution:
As root, execute the following commands:
# cd /usr/lib
# chmod a-s,go-w lpshut lpmove accept reject lpadmin
# chmod go-ws lpsched vadmin/serial_ports vadmin/users vadmin/disks
# cd /usr/bin
# chmod a-s,go-w disable enable
# chmod go-ws cancel lp lpstat
If the eoe2.sw.vadmin software is not installed, you may
ignore any warning messages from chmod such as:
"chmod: WARNING: can't access vadmin/serial_ports"
If system software should ever be reinstalled from pre-4.0.5
media or restored from a backup tape created before the patch was
applied, repeat the above procedure before enabling logins by
normal users.