exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

cyanuro.txt

cyanuro.txt
Posted Feb 11, 2008
Authored by Luigi Auriemma | Site aluigi.org

The Opium OPI Server versions 4.10.1028 and below along with a large amount of cyanPrintIP products suffer from a format string vulnerability in ReportSysLogEvent as well as a server crash flaw.

tags | advisory
SHA-256 | 73f875d8944de4b42d99e9155d5fd14c3284bed1f200ad31d230dea4ef1f673d

cyanuro.txt

Change Mirror Download

#######################################################################

Luigi Auriemma

Applications: Opium OPI Server
http://www.cyansoftware.com/Opium_OPI.htm
cyanPrintIP Easy OPI
http://www.cyansoftware.com/cyanPrintIP_Easy_OPI.htm
cyanPrintIP
http://www.cyansoftware.com/cyanPrintIP.htm
Versions: Opium OPI Server <= 4.10.1028
cyanPrintIP Easy OPI <= 4.10.1030
cyanPrintIP Professional <= 4.10.1030
cyanPrintIP Workstation <= 4.10.836
cyanPrintIP Standard <= 4.10.940
cyanPrintIP Basic <= 4.10.1030
Platforms: Windows
Bugs: A] format string in ReportSysLogEvent
B] service crash through "Send queue state" commands
Exploitation: remote
Date: 11 Feb 2008
Author: Luigi Auriemma
e-mail: aluigi@autistici.org
web: aluigi.org


#######################################################################


1) Introduction
2) Bugs
3) The Code
4) Fix


#######################################################################

===============
1) Introduction
===============


Opium and cyanPrintIP are a family of LPD products for the network
sharing of printers.


#######################################################################

=======
2) Bugs
=======

-------------------------------------
A] format string in ReportSysLogEvent
-------------------------------------

The LPD servers are affected by a format string vulnerability in the
ReportSysLogEvent function used for logging.
The best way for exploiting this vulnerability is through a malformed
queue name which will be used to build a "Print queue" error message
directly passed to vsprintf without the needed format argument.

After the exploitation will be created a dump and the server will be
automatically restarted by the Restart process.


----------------------------------------------------
B] service crash through "Send queue state" commands
----------------------------------------------------

The servers are not able to handle the two "Send queue state" LPD
commands (3 and 4) when received at the beginning of the connection, so
when not expected by it.

The result is the immediate crash/termination of the server which will
be not restarted automatically.


#######################################################################

===========
3) The Code
===========


http://aluigi.org/poc/cyanuro.zip


#######################################################################

======
4) Fix
======


No fix


#######################################################################


---
Luigi Auriemma
http://aluigi.org
Login or Register to add favorites

File Archive:

June 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jun 1st
    18 Files
  • 2
    Jun 2nd
    13 Files
  • 3
    Jun 3rd
    0 Files
  • 4
    Jun 4th
    0 Files
  • 5
    Jun 5th
    0 Files
  • 6
    Jun 6th
    0 Files
  • 7
    Jun 7th
    0 Files
  • 8
    Jun 8th
    0 Files
  • 9
    Jun 9th
    0 Files
  • 10
    Jun 10th
    0 Files
  • 11
    Jun 11th
    0 Files
  • 12
    Jun 12th
    0 Files
  • 13
    Jun 13th
    0 Files
  • 14
    Jun 14th
    0 Files
  • 15
    Jun 15th
    0 Files
  • 16
    Jun 16th
    0 Files
  • 17
    Jun 17th
    0 Files
  • 18
    Jun 18th
    0 Files
  • 19
    Jun 19th
    0 Files
  • 20
    Jun 20th
    0 Files
  • 21
    Jun 21st
    0 Files
  • 22
    Jun 22nd
    0 Files
  • 23
    Jun 23rd
    0 Files
  • 24
    Jun 24th
    0 Files
  • 25
    Jun 25th
    0 Files
  • 26
    Jun 26th
    0 Files
  • 27
    Jun 27th
    0 Files
  • 28
    Jun 28th
    0 Files
  • 29
    Jun 29th
    0 Files
  • 30
    Jun 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close