what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

sa96-18

sa96-18
Posted Sep 23, 1999

Buffer overflow in lpr

tags | overflow
systems | freebsd
SHA-256 | b63ca2ed1e5f1abba47cdb29fb31ff08c15085b4cb78c39ba05ec6ded067a674

sa96-18

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----

=============================================================================
FreeBSD-SA-96:18 Security Advisory
FreeBSD, Inc.

Topic: Buffer overflow in lpr

Category: core
Module: lpr
Announced: 1996-11-25
Affects: FreeBSD 2.*
Corrected: FreeBSD-current as of 1996/10/27
FreeBSD-stable as of 1996/11/01
FreeBSD only: no

Patches: ftp://freebsd.org/pub/CERT/patches/SA-96:18/

=============================================================================

I. Background

The lpr program is used to print files. It is standard software
in the FreeBSD operating system.

This advisory is based on AUSCERT's advisory AA-96.12. The FreeBSD
security-officers would like to thank AUSCERT for their efforts.


II. Problem Description

Due to its nature, the lpr program is setuid root. Unfortunately,
the program does not do sufficient bounds checking on arguments which
are supplied by users. As a result it is possible to overwrite the
internal stack space of the program while it's executing. This can
allow an intruder to execute arbitrary code by crafting a carefully
designed argument to lpr. As lpr runs as root this allows intruders
to run arbitrary commands as root.


III. Impact
Local users can gain root privileges.


IV. Workaround

AUSCERT has developed a wrapper to help prevent lpr being exploited
using this vulnerability. This wrapper, including installation
instructions, can be found in
ftp://ftp.auscert.org.au/pub/auscert/advisory/
AA-96.12.lpr.buffer.overrun.vul

V. Solution

Apply one of the following patches. Patches are provided for
FreeBSD-current (before 1996/10/27) (SA-96:18-solution.current)
FreeBSD-2.0.5, FreeBSD-2.1.0, FreeBSD-2.1.5 and
FreeBSd-stable (before 1996/11/01) (SA-96:18-solution.2xx)

Patches can be found on ftp://freebsd.org/pub/CERT/patches/SA-96:18

=============================================================================
FreeBSD, Inc.

Web Site: http://www.freebsd.org/
Confidential contacts: security-officer@freebsd.org
PGP Key: ftp://freebsd.org/pub/CERT/public_key.asc
Security notifications: security-notifications@freebsd.org
Security public discussion: security@freebsd.org

Notice: Any patches in this document may not apply cleanly due to
modifications caused by digital signature or mailer software.
Please reference the URL listed at the top of this document
for original copies of all patches if necessary.
=============================================================================


-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAwUBMpn2wlUuHi5z0oilAQGjhgP/XON+ydyxEm2eiY87pmdLhlF3Qwz//YRB
MtoVrr2PffZ4FKXCcpQbG30F9AYDL0ZD19Uo89g8rzOfKhhwanFdvixqoGAr15h0
jyLdLv0YoStbehBuyMUHebUplctYmTpHskz0Zhv0OOVtlUuCgh0Y2V4WfZI6RVsu
0B3ZMw8JRQo=
=cw23
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close