SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#388183

IBM AIX line printer daemon contains a buffer overflow in kill_print()

Overview

The Line Printer daemon (lpd) shipped with AIX systems contains a buffer overflow in kill_print() that potentially allow a malicious remote user to gain root privileges.

I. Description

A buffer overflow exists in the kill_print() function of the line printer daemon (lpd) on AIX systems. An intruder could exploit this vulnerability to obtain root privileges or cause a denial of service (DoS). The intruder would need to be listed in the victim's /etc/hosts.lpd or /etc/hosts.equiv file, however, to exploit this vulnerability.

II. Impact

An intruder could exploit this vulnerability to obtain root privileges, or cause a denial of service (DoS).

III. Solution

IBM has released a VULNERABILITY SUMMARY. Please see the vendor statement for patches and instructions.

Systems Affected

VendorStatusDate Updated
AppleNot Vulnerable9-Nov-2001
CalderaNot Vulnerable1-Nov-2001
Compaq Computer CorporationUnknown5-Nov-2001
CrayNot Vulnerable1-Nov-2001
EngardeNot Vulnerable1-Nov-2001
FreeBSDNot Vulnerable5-Nov-2001
FujitsuNot Vulnerable1-Nov-2001
IBMVulnerable16-Oct-2001
Red HatNot Vulnerable8-Nov-2001
SunNot Vulnerable1-Nov-2001

References


http://www.uniras.gov.uk/l1/l2/l3/brief2001/UNIRAS%20Briefing%20-%2016301%20-%20IBM%20%20-%20Buffer%20Overflow%20Vulnerabilities%20in%20lpd.txt
http://archives.neohapsis.com/archives/bugtraq/2001-09/0084.html

Credit

The CERT/CC wishes to thank IBM for their help in identifying and analyzing this vulnerability.

This document was written by Jason Rafail.

Other Information

Date Public09/11/2001
Date First Published10/16/2001 03:00:20 PM
Date Last Updated01/03/2002
CERT Advisory 
CVE-ID(s)CAN-2001-0671
NVD-ID(s)CAN-2001-0671
US-CERT Technical Alerts 
Metric9.84
Document Revision12

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2001 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader