NIPrint LPD-LPR Print Server Remote Buffer Overrun Vulnerability
BID:8968
Info
NIPrint LPD-LPR Print Server Remote Buffer Overrun Vulnerability
| Bugtraq ID: | 8968 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2003 12:00AM |
| Updated: | Jun 22 2006 08:15PM |
| Credit: | The discovery of this vulnerability has been credited to SNOSoft. |
| Vulnerable: |
Network Instruments NIPrint LPD-LPR Print Server 4.10 |
| Not Vulnerable: | |
Discussion
NIPrint LPD-LPR Print Server Remote Buffer Overrun Vulnerability
NIPrint LPD-LPR Print Server is reported prone to a remotely exploitable buffer-overrun condition. The problem occurs because the application fails to perform sufficient boundary checks when handling data received over the printer port. As a result, a remote attacker may be able to corrupt process memory in such a way that arbitrary code may be executed.
NIPrint LPD-LPR Print Server is reported prone to a remotely exploitable buffer-overrun condition. The problem occurs because the application fails to perform sufficient boundary checks when handling data received over the printer port. As a result, a remote attacker may be able to corrupt process memory in such a way that arbitrary code may be executed.
Exploit / POC
NIPrint LPD-LPR Print Server Remote Buffer Overrun Vulnerability
SNOSoft has indicated that proof-of-concept code has been developed for this issue, but it will not be made available to the public.
An exploit has been made available by xCrZx, however, and is available below.
A Metasploit framework exploit module is available.
SNOSoft has indicated that proof-of-concept code has been developed for this issue, but it will not be made available to the public.
An exploit has been made available by xCrZx, however, and is available below.
A Metasploit framework exploit module is available.
Solution / Fix
NIPrint LPD-LPR Print Server Remote Buffer Overrun Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
NIPrint LPD-LPR Print Server Remote Buffer Overrun Vulnerability
References:
References:
- NIPrint Product Page (Network Instruments)
- NIPrint remote exploit (Crazy Einstein
) - SRT2003-11-02-0115 - NIPrint LPD-LPR Remote overflow (KF
)