Multiple Vendor LPRM Local Buffer Overflow Vulnerability
BID:7025
Info
Multiple Vendor LPRM Local Buffer Overflow Vulnerability
| Bugtraq ID: | 7025 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0144 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 22 1998 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | Discovery credited to Niall Smart <[email protected]>. |
| Vulnerable: |
SGI IRIX 6.5.19 SGI IRIX 6.5.18 SGI IRIX 6.5.17 SGI IRIX 6.5.16 SGI IRIX 6.5.15 SGI IRIX 6.5.14 SGI IRIX 6.5.13 SGI IRIX 6.5.12 SGI IRIX 6.5.11 SGI IRIX 6.5.10 SGI IRIX 6.5.9 SGI IRIX 6.5.8 SGI IRIX 6.5.7 SGI IRIX 6.5.6 SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 OpenBSD OpenBSD 2.9 OpenBSD OpenBSD 2.8 OpenBSD OpenBSD 2.7 OpenBSD OpenBSD 2.6 OpenBSD OpenBSD 2.5 OpenBSD OpenBSD 2.4 OpenBSD OpenBSD 2.3 OpenBSD OpenBSD 2.2 OpenBSD OpenBSD 2.1 OpenBSD OpenBSD 2.0 OpenBSD OpenBSD 3.2 OpenBSD OpenBSD 3.1 OpenBSD OpenBSD 3.0 lprold lprold 3.0.48 lpr-ppd lpr-ppd 0.72 FreeBSD FreeBSD 2.2.6 FreeBSD FreeBSD 2.2.5 FreeBSD FreeBSD 2.2.4 FreeBSD FreeBSD 2.2.3 FreeBSD FreeBSD 2.2.2 FreeBSD FreeBSD 2.2 BSD lpr 0.72 BSD lpr 0.48 BSD lpr 2000.05.07 |
| Not Vulnerable: |
SGI IRIX 6.5.20 |
Discussion
Multiple Vendor LPRM Local Buffer Overflow Vulnerability
It has been reported that a vulnerability in the handling of some types of requests exists in lprm. When an attacker sends a maliciously crafted string to a configured printer through the lprm command, it may be possible to execute code.
It has been reported that a vulnerability in the handling of some types of requests exists in lprm. When an attacker sends a maliciously crafted string to a configured printer through the lprm command, it may be possible to execute code.
Solution / Fix
Multiple Vendor LPRM Local Buffer Overflow Vulnerability
Solution:
A patch for OpenBSD has been made available.
SGI has released an advisory (20030406-01-P) containing fixes that address this issue. Users are advised to upgrade as soon as possible.
Debian has revised its advisory. New fixes for Debian 2.2 (potato) are available. Please see the referenced advisory for further details.
Mandrake has released a security advisory (MDKSA-2003:059) containing fixes which address this issue. Users are advised to upgrade as soon as possible.
OpenBSD OpenBSD 3.2
OpenBSD OpenBSD 3.1
BSD lpr 2000.05.07
BSD lpr 0.48
BSD lpr 0.72
lpr-ppd lpr-ppd 0.72
lprold lprold 3.0.48
SGI IRIX 6.5.14
SGI IRIX 6.5.15
SGI IRIX 6.5.16
SGI IRIX 6.5.17
SGI IRIX 6.5.18
SGI IRIX 6.5.19
Solution:
A patch for OpenBSD has been made available.
SGI has released an advisory (20030406-01-P) containing fixes that address this issue. Users are advised to upgrade as soon as possible.
Debian has revised its advisory. New fixes for Debian 2.2 (potato) are available. Please see the referenced advisory for further details.
Mandrake has released a security advisory (MDKSA-2003:059) containing fixes which address this issue. Users are advised to upgrade as soon as possible.
OpenBSD OpenBSD 3.2
-
OpenBSD 010_lprm.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch
OpenBSD OpenBSD 3.1
-
OpenBSD 023_lprm.patch
Patch for OpenBSD 3.1.
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/023_lprm.patch
BSD lpr 2000.05.07
-
Debian lpr_2000.05.07-4.3_alpha.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/l/lpr/lpr_2000.05.07-4.3_ alpha.deb -
Debian lpr_2000.05.07-4.3_arm.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/l/lpr/lpr_2000.05.07-4.3_ arm.deb -
Debian lpr_2000.05.07-4.3_hppa.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/l/lpr/lpr_2000.05.07-4.3_ hppa.deb -
Debian lpr_2000.05.07-4.3_i386.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/l/lpr/lpr_2000.05.07-4.3_ i386.deb -
Debian lpr_2000.05.07-4.3_ia64.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/l/lpr/lpr_2000.05.07-4.3_ ia64.deb -
Debian lpr_2000.05.07-4.3_m68k.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/l/lpr/lpr_2000.05.07-4.3_ m68k.deb -
Debian lpr_2000.05.07-4.3_mips.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/l/lpr/lpr_2000.05.07-4.3_ mips.deb -
Debian lpr_2000.05.07-4.3_mipsel.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/l/lpr/lpr_2000.05.07-4.3_ mipsel.deb -
Debian lpr_2000.05.07-4.3_powerpc.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/l/lpr/lpr_2000.05.07-4.3_ powerpc.deb -
Debian lpr_2000.05.07-4.3_s390.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/l/lpr/lpr_2000.05.07-4.3_ s390.deb -
Debian lpr_2000.05.07-4.3_sparc.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/l/lpr/lpr_2000.05.07-4.3_ sparc.deb
BSD lpr 0.48
-
Debian lpr_0.48-1.1_alpha.deb
Debian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.1_alpha. deb -
Debian lpr_0.48-1.1_arm.deb
Debian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.1_arm.de b -
Debian lpr_0.48-1.1_i386.deb
Debian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.1_i386.d eb -
Debian lpr_0.48-1.1_m68k.deb
Debian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.1_m68k.d eb -
Debian lpr_0.48-1.1_powerpc.deb
Debian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.1_powerp c.deb -
Debian lpr_0.48-1.1_sparc.deb
Debian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.1_sparc. deb -
Debian lpr_0.48-1.2_alpha.deb
http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.2_alpha. deb -
Debian lpr_0.48-1.2_arm.deb
http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.2_arm.de b -
Debian lpr_0.48-1.2_i386.deb
http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.2_i386.d eb -
Debian lpr_0.48-1.2_m68k.deb
http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.2_m68k.d eb -
Debian lpr_0.48-1.2_powerpc.deb
http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.2_powerp c.deb -
Debian lpr_0.48-1.2_sparc.deb
http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.2_sparc. deb
BSD lpr 0.72
-
Mandrake lpr-0.72-3.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lpr-0.72-3.1mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php
lpr-ppd lpr-ppd 0.72
-
Debian lpr-ppd_0.72-2.1_alpha.deb
http://security.debian.org/pool/updates/main/l/lpr-ppd/lpr-ppd_0.72-2. 1_alpha.deb -
Debian lpr-ppd_0.72-2.1_arm.deb
http://security.debian.org/pool/updates/main/l/lpr-ppd/lpr-ppd_0.72-2. 1_arm.deb -
Debian lpr-ppd_0.72-2.1_hppa.deb
http://security.debian.org/pool/updates/main/l/lpr-ppd/lpr-ppd_0.72-2. 1_hppa.deb -
Debian lpr-ppd_0.72-2.1_i386.deb
http://security.debian.org/pool/updates/main/l/lpr-ppd/lpr-ppd_0.72-2. 1_i386.deb -
Debian lpr-ppd_0.72-2.1_ia64.deb
http://security.debian.org/pool/updates/main/l/lpr-ppd/lpr-ppd_0.72-2. 1_ia64.deb -
Debian lpr-ppd_0.72-2.1_m68k.deb
http://security.debian.org/pool/updates/main/l/lpr-ppd/lpr-ppd_0.72-2. 1_m68k.deb -
Debian lpr-ppd_0.72-2.1_mips.deb
http://security.debian.org/pool/updates/main/l/lpr-ppd/lpr-ppd_0.72-2. 1_mips.deb -
Debian lpr-ppd_0.72-2.1_mipsel.deb
http://security.debian.org/pool/updates/main/l/lpr-ppd/lpr-ppd_0.72-2. 1_mipsel.deb -
Debian lpr-ppd_0.72-2.1_powerpc.deb
http://security.debian.org/pool/updates/main/l/lpr-ppd/lpr-ppd_0.72-2. 1_powerpc.deb -
Debian lpr-ppd_0.72-2.1_s390.deb
http://security.debian.org/pool/updates/main/l/lpr-ppd/lpr-ppd_0.72-2. 1_s390.deb -
Debian lpr-ppd_0.72-2.1_sparc.deb
http://security.debian.org/pool/updates/main/l/lpr-ppd/lpr-ppd_0.72-2. 1_sparc.deb
lprold lprold 3.0.48
-
SuSE lprold-3.0.48-270.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.1/n1/lprold-3.0.48-270.alpha. rpm -
SuSE lprold-3.0.48-273.sparc.rpm
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n1/lprold-3.0.48-273.spar c.rpm -
SuSE lprold-3.0.48-297.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/n1/lprold-3.0.48-297.ppc.rp m -
SuSE lprold-3.0.48-297.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n1/lprold-3.0.48-297.ppc.rp m -
SuSE lprold-3.0.48-407.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/n1/lprold-3.0.48-407.i386. rpm -
SuSE lprold-3.0.48-407.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n1/lprold-3.0.48-407.i386. rpm -
SuSE lprold-3.0.48-408.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n1/lprold-3.0.48-408.i386. rpm
SGI IRIX 6.5.14
-
SGI 5048
ftp://patches.sgi.com/support/free/security/patches/ -
SGI 5071
ftp://patches.sgi.com/support/free/security/patches/
SGI IRIX 6.5.15
-
SGI 5048
ftp://patches.sgi.com/support/free/security/patches/ -
SGI 5071
ftp://patches.sgi.com/support/free/security/patches/
SGI IRIX 6.5.16
-
SGI 5048
ftp://patches.sgi.com/support/free/security/patches/ -
SGI 5071
ftp://patches.sgi.com/support/free/security/patches/
SGI IRIX 6.5.17
-
SGI 5048
ftp://patches.sgi.com/support/free/security/patches/ -
SGI 5071
ftp://patches.sgi.com/support/free/security/patches/
SGI IRIX 6.5.18
-
SGI 5048
ftp://patches.sgi.com/support/free/security/patches/ -
SGI 5071
ftp://patches.sgi.com/support/free/security/patches/
SGI IRIX 6.5.19