Multiple Vendor lpr Buffer Overrun Vulnerability
BID:707
Info
Multiple Vendor lpr Buffer Overrun Vulnerability
| Bugtraq ID: | 707 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 25 1996 12:00AM |
| Updated: | Oct 25 1996 12:00AM |
| Credit: | The first report of an overflow problem in lpr was made on Bugtraq by bloodmask <[email protected]> 13 August 1996. This particular vulnerability with exploit was reported by Vadim Kolontsov <[email protected]> to Bugtraq on 25 October 1996. |
| Vulnerable: |
Sun SunOS 4.1.4 Sun SunOS 4.1.3 _U1 SGI IRIX 6.4 SGI IRIX 6.3 SGI IRIX 6.2 SGI IRIX 6.1 SGI IRIX 6.0.1 SGI IRIX 6.0 SGI IRIX 5.3 SGI IRIX 5.2 SGI IRIX 5.1.1 SGI IRIX 5.1 SGI IRIX 5.0.1 SGI IRIX 5.0 NeXT NeXTstep 4.1 NeXT NeXTstep 4.0 FreeBSD FreeBSD 2.1.5 FreeBSD FreeBSD 2.1 FreeBSD FreeBSD 2.0.5 FreeBSD FreeBSD 2.0 BSDI BSD/OS 2.1 |
| Not Vulnerable: |
NeXT OpenStep 4.2 FreeBSD FreeBSD 2.2 FreeBSD FreeBSD 2.1.6 BSDI BSD/OS 3.0 |
Discussion
Multiple Vendor lpr Buffer Overrun Vulnerability
Due to insufficient bounds checking on arguments (in this case -C) which are supplied by users, it is possible to overwrite the internal stack space of the lpr program while it is executing. This can allow an intruder to cause lpr to execute arbitrary commands by supplying a carefully designed argument to lpr. These commands will be run with the privileges of the lpr program. When lpr is installed setuid or setgid, it may allow intruders to gain those privileges.
Due to insufficient bounds checking on arguments (in this case -C) which are supplied by users, it is possible to overwrite the internal stack space of the lpr program while it is executing. This can allow an intruder to cause lpr to execute arbitrary commands by supplying a carefully designed argument to lpr. These commands will be run with the privileges of the lpr program. When lpr is installed setuid or setgid, it may allow intruders to gain those privileges.
Exploit / POC
Multiple Vendor lpr Buffer Overrun Vulnerability
An exploit has been made available.
An exploit has been made available.
Solution / Fix
Multiple Vendor lpr Buffer Overrun Vulnerability
Solution:
It is advised to install vendor fixes for this problem.
Solution:
It is advised to install vendor fixes for this problem.
References
Multiple Vendor lpr Buffer Overrun Vulnerability
References:
References: