LPRng PSBanner Insecure Temporary File Creation Vulnerability
BID:7334
Info
LPRng PSBanner Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 7334 |
| Class: | Access Validation Error |
| CVE: |
CVE-2003-0136 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 14 2003 12:00AM |
| Updated: | Jul 11 2009 09:06PM |
| Credit: | Discovery of this vulnerability has been credited to Karol Lewandowski. |
| Vulnerable: |
Redhat Linux Advanced Work Station 2.1 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 AStArt Technologies LPRng 3.8.19 AStArt Technologies LPRng 3.8.12 AStArt Technologies LPRng 3.8.10 .1 AStArt Technologies LPRng 3.8.9 AStArt Technologies LPRng 3.8.6 AStArt Technologies LPRng 3.7.4 AStArt Technologies LPRng 3.6.24 |
| Not Vulnerable: |
AStArt Technologies LPRng 3.8.10 .1.2 |
Discussion
LPRng PSBanner Insecure Temporary File Creation Vulnerability
LPRng psbanner filter has been reported prone to an insecure temporary file creation vulnerability.
Under certain configurations, the psbanner filter creates temporary files for debugging purposes, in an insecure manner.
This vulnerability may lead to symbolic link attacks within the context of the user running the vulnerable utility.
LPRng psbanner filter has been reported prone to an insecure temporary file creation vulnerability.
Under certain configurations, the psbanner filter creates temporary files for debugging purposes, in an insecure manner.
This vulnerability may lead to symbolic link attacks within the context of the user running the vulnerable utility.
Exploit / POC
LPRng PSBanner Insecure Temporary File Creation Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
LPRng PSBanner Insecure Temporary File Creation Vulnerability
Solution:
Yellow Dog Linux has released an advisory (YDU-20030602-5) and fixes to address this issue. Users are recommended to run the 'apt-get' utility by issuing the following commands.
apt-get update
apt-get install LPRng
Debian have released an advisory (DSA 285-1) and fixes to address this issue. Further information on how to obtain and supply fixes can be found in the attached Debian advisory.
Red Hat has released a security advisory (RHSA-2003:142-01) containing fixes which address this issue. Users are advised to upgrade as soon as possible.
Red Hat has released an advisory (RHSA-2003:150-04). Updated packages are available through the Red Hat Network (http://rhn.redhat.com/).
Immunix has released a security advisory (IMNX-2003-7+-013-01) containing a fix to address this issue.
Gentoo Linux has released an advisory. Users who have installed net-print/lprng are advised to upgrade to lprng-3.8.12-r1 by issuing the following commands:
emerge sync
emerge lprng
emerge clean
Fixes:
AStArt Technologies LPRng 3.6.24
AStArt Technologies LPRng 3.7.4
AStArt Technologies LPRng 3.8.10 .1
AStArt Technologies LPRng 3.8.12
AStArt Technologies LPRng 3.8.19
AStArt Technologies LPRng 3.8.6
AStArt Technologies LPRng 3.8.9
Solution:
Yellow Dog Linux has released an advisory (YDU-20030602-5) and fixes to address this issue. Users are recommended to run the 'apt-get' utility by issuing the following commands.
apt-get update
apt-get install LPRng
Debian have released an advisory (DSA 285-1) and fixes to address this issue. Further information on how to obtain and supply fixes can be found in the attached Debian advisory.
Red Hat has released a security advisory (RHSA-2003:142-01) containing fixes which address this issue. Users are advised to upgrade as soon as possible.
Red Hat has released an advisory (RHSA-2003:150-04). Updated packages are available through the Red Hat Network (http://rhn.redhat.com/).
Immunix has released a security advisory (IMNX-2003-7+-013-01) containing a fix to address this issue.
Gentoo Linux has released an advisory. Users who have installed net-print/lprng are advised to upgrade to lprng-3.8.12-r1 by issuing the following commands:
emerge sync
emerge lprng
emerge clean
Fixes:
AStArt Technologies LPRng 3.6.24
-
Immunix LPRng-3.6.24-2_imnx_1.i386.rpm
http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/LPRng-3.6.24-2_i mnx_1.i386.rpm
AStArt Technologies LPRng 3.7.4
-
Red Hat LPRng-3.7.4-23.2.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/LPRng-3.7.4-23.2.i386.rpm -
Red Hat LPRng-3.7.4-28.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/LPRng-3.7.4-28.2.i386.rpm -
Red Hat LPRng-3.7.4-28.2.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/LPRng-3.7.4-28.2.ia64.rpm
AStArt Technologies LPRng 3.8.10 .1
-
Debian lprng_3.8.10-1.2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lprng/lprng_3.8.10-1.2_ alpha.deb -
Debian lprng_3.8.10-1.2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lprng/lprng_3.8.10-1.2_ arm.deb -
Debian lprng_3.8.10-1.2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lprng/lprng_3.8.10-1.2_ hppa.deb -
Debian lprng_3.8.10-1.2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lprng/lprng_3.8.10-1.2_ i386.deb -
Debian lprng_3.8.10-1.2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lprng/lprng_3.8.10-1.2_ ia64.deb -
Debian lprng_3.8.10-1.2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lprng/lprng_3.8.10-1.2_ m68k.deb -
Debian lprng_3.8.10-1.2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lprng/lprng_3.8.10-1.2_ mips.deb -
Debian lprng_3.8.10-1.2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lprng/lprng_3.8.10-1.2_ mipsel.deb -
Debian lprng_3.8.10-1.2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lprng/lprng_3.8.10-1.2_ powerpc.deb -
Debian lprng_3.8.10-1.2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lprng/lprng_3.8.10-1.2_ s390.deb -
Debian lprng_3.8.10-1.2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lprng/lprng_3.8.10-1.2_ sparc.deb
AStArt Technologies LPRng 3.8.12
-
Mandrake LPRng-3.8.12-2.1mdk.i586.rpm
Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake LPRng-3.8.12-2.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php
AStArt Technologies LPRng 3.8.19
-
Red Hat LPRng-3.8.19-3.1.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/LPRng-3.8.19-3.1.i386.rpm
AStArt Technologies LPRng 3.8.6
-
Mandrake LPRng-3.8.6-2.2mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake LPRng-3.8.6-2.2mdk.ppc.rpm
Mandrake Linux 8.2/PPC
http://www.mandrakesecure.net/en/ftp.php
AStArt Technologies LPRng 3.8.9
-
Red Hat LPRng-3.8.9-4.1.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/LPRng-3.8.9-4.1.i386.rpm -
Red Hat LPRng-3.8.9-6.1.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/LPRng-3.8.9-6.1.i386.rpm
References
LPRng PSBanner Insecure Temporary File Creation Vulnerability
References:
References:
- RHSA-2003:150-04 (Red Hat)