LPRNG html2ps Remote Command Execution Vulnerability
BID:6079
Info
LPRNG html2ps Remote Command Execution Vulnerability
| Bugtraq ID: | 6079 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1275 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 31 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Vulnerability announced in a SuSE advisory. |
| Vulnerable: |
SuSE Linux 8.1 SuSE Linux 8.0 SuSE Linux 7.3 SuSE Linux 7.2 SuSE Linux 7.1 SuSE Linux 7.0 SGI IRIX 6.5.22 SGI IRIX 6.5.21 m SGI IRIX 6.5.21 f SGI IRIX 6.5.20 m SGI IRIX 6.5.20 f SGI IRIX 6.5.19 m SGI IRIX 6.5.19 f SGI IRIX 6.5.18 m SGI IRIX 6.5.18 f SGI IRIX 6.5.17 m SGI IRIX 6.5.17 f SGI IRIX 6.5.16 SGI IRIX 6.5.15 SGI IRIX 6.5.14 SGI IRIX 6.5.13 SGI IRIX 6.5.12 SGI IRIX 6.5.11 SGI IRIX 6.5.10 SGI IRIX 6.5.9 SGI IRIX 6.5.8 SGI IRIX 6.5.7 SGI IRIX 6.5.6 SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 html2ps html2ps 1.0 b3 html2ps html2ps 1.0 b2 html2ps html2ps 1.0 B1 |
| Not Vulnerable: | |
Discussion
LPRNG html2ps Remote Command Execution Vulnerability
A vulnerability has been discovered in the html2ps filter which is included in the lprng print system.
It has been reported that it is possible for a remote attacker to execute arbitrary commands. The attacker must reportedly already have access to the 'lp' (or equivalent) account to exploit this condition.
This cause of this vulnerability is that html2ps may open files using unsanitized input that may be supplied by a potentially malicious user.
A vulnerability has been discovered in the html2ps filter which is included in the lprng print system.
It has been reported that it is possible for a remote attacker to execute arbitrary commands. The attacker must reportedly already have access to the 'lp' (or equivalent) account to exploit this condition.
This cause of this vulnerability is that html2ps may open files using unsanitized input that may be supplied by a potentially malicious user.
Exploit / POC
LPRNG html2ps Remote Command Execution Vulnerability
Exploit code has been published:
Exploit code has been published:
Solution / Fix
LPRNG html2ps Remote Command Execution Vulnerability
Solution:
SGI has released advisory 20040104-01-P to address this issue. Patch 5424 will be released for IRIX versions later than 6.5.17. Users should upgrade to one of these versions and then apply the patch when it is available. Further details can be found in the attached advisory.
Fixes are available:
html2ps html2ps 1.0 b3
html2ps html2ps 1.0 B1
SuSE Linux 7.0
SuSE Linux 7.1
SuSE Linux 7.2
SuSE Linux 7.3
SuSE Linux 8.0
SuSE Linux 8.1
Solution:
SGI has released advisory 20040104-01-P to address this issue. Patch 5424 will be released for IRIX versions later than 6.5.17. Users should upgrade to one of these versions and then apply the patch when it is available. Further details can be found in the attached advisory.
Fixes are available:
html2ps html2ps 1.0 b3
-
Debian html2ps_1.0b3-1.1_all.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/h/html2ps/html2ps_1.0b3-1 .1_all.deb -
Debian html2ps_1.0b3-1.2_all.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/h/html2ps/html2ps_1.0b3-1 .2_all.deb -
S.u.S.E. html2ps-1.0b3-456.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/gra1/html2ps-1.0b3-456.i38 6.rpm -
S.u.S.E. html2ps-1.0b3-457.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.3/gra1/html2ps-1.0b3-457.i38 6.rpm -
S.u.S.E. html2ps-1.0b3-458.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/html2ps-1.0b3-458 .i586.rpm -
S.u.S.E. html2ps-1.0b3-88.sparc.rpm
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/gra1/html2ps-1.0b3-88.spa rc.rpm -
S.u.S.E. lpdfilter-0.42-155.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/ap1/lpdfilter-0.42-155.i38 6.rpm -
S.u.S.E. lpdfilter-0.43-63.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/lpdfilter-0.43-63 .i586.rpm
html2ps html2ps 1.0 B1
-
Debian html2ps_1.0b1-8.2_all.deb
Debian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/h/html2ps/html2ps_1.0b1-8 .2_all.deb -
S.u.S.E. html2ps-1.0b1-302.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/gra1/html2ps-1.0b1-302.ppc. rpm -
S.u.S.E. html2ps-1.0b1-303.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/gra1/html2ps-1.0b1-303.ppc. rpm -
S.u.S.E. html2ps-1.0b1-328.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.0/gra1/html2ps-1.0b1-328.alph a.rpm -
S.u.S.E. html2ps-1.0b1-428.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.0/gra1/html2ps-1.0b1-428.i38 6.rpm -
S.u.S.E. html2ps-1.0b1-431.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/gra1/html2ps-1.0b1-431.i38 6.rpm -
S.u.S.E. html2ps-1.0b1-432.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/gra1/html2ps-1.0b1-432.i38 6.rpm
SuSE Linux 7.0
-
S.u.S.E. html2ps-1.0b1-302.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/gra1/html2ps-1.0b1-302.ppc. rpm -
S.u.S.E. html2ps-1.0b1-328.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.0/gra1/html2ps-1.0b1-328.alph a.rpm -
S.u.S.E. html2ps-1.0b1-428.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.0/gra1/html2ps-1.0b1-428.i38 6.rpm -
S.u.S.E. html2ps-1.0b1-302.src.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/zq1/html2ps-1.0b1-302.src.r pm -
S.u.S.E. html2ps-1.0b1-328.src.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.0/zq1/html2ps-1.0b1-328.src.r pm -
S.u.S.E. html2ps-1.0b1-428.src.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.0/zq1/html2ps-1.0b1-428.src. rpm
SuSE Linux 7.1
-
S.u.S.E. html2ps-1.0b1-303.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/gra1/html2ps-1.0b1-303.ppc. rpm -
S.u.S.E. html2ps-1.0b1-431.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/gra1/html2ps-1.0b1-431.i38 6.rpm -
S.u.S.E. html2ps-1.0b1-303.src.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/zq1/html2ps-1.0b1-303.src.r pm -
S.u.S.E. html2ps-1.0b1-431.src.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/zq1/html2ps-1.0b1-431.src. rpm
SuSE Linux 7.2
-
S.u.S.E. html2ps-1.0b1-432.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/gra1/html2ps-1.0b1-432.i38 6.rpm -
S.u.S.E. html2ps-1.0b1-432.src.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/zq1/html2ps-1.0b1-432.src. rpm
SuSE Linux 7.3
-
S.u.S.E. html2ps-1.0b3-457.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.3/gra1/html2ps-1.0b3-457.i38 6.rpm -
S.u.S.E. html2ps-1.0b3-88.sparc.rpm
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/gra1/html2ps-1.0b3-88.spa rc.rpm -
S.u.S.E. html2ps-1.0b3-457.src.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.3/zq1/html2ps-1.0b3-457.src. rpm -
S.u.S.E. html2ps-1.0b3-88.src.rpm
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/zq1/html2ps-1.0b3-88.src. rpm
SuSE Linux 8.0
-
S.u.S.E. html2ps-1.0b3-456.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/gra1/html2ps-1.0b3-456.i38 6.rpm -
S.u.S.E. lpdfilter-0.42-155.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/ap1/lpdfilter-0.42-155.i38 6.rpm -
S.u.S.E. html2ps-1.0b3-456.src.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/html2ps-1.0b3-456.src. rpm -
S.u.S.E. lpdfilter-0.42-155.src.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/lpdfilter-0.42-155.src .rpm
SuSE Linux 8.1
-
S.u.S.E. html2ps-1.0b3-458.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/html2ps-1.0b3-458 .i586.rpm -
S.u.S.E. lpdfilter-0.43-63.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/lpdfilter-0.43-63 .i586.rpm -
S.u.S.E. html2ps-1.0b3-458.src.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/src/html2ps-1.0b3-458. src.rpm -
S.u.S.E. lpdfilter-0.43-63.src.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/src/lpdfilter-0.43-63. src.rpm
References
LPRNG html2ps Remote Command Execution Vulnerability
References:
References: