SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#860296

CDE dtprintinfo contains local buffer overflow in Help window via clipboard copy

Overview

The CDE Print Viewer program dtprintinfo provides a graphical interface display the status of print queues and print jobs. By using the clipboard to overflow the search field in the Help window of dtprintinfo, a local attacker can execute arbitrary code on the system as root.

I. Description

There is a buffer overflow in the graphical program used to view print job status in CDE-aware desktop environments. Since dtprintinfo is commonly set to be setuid root, this defect could allow a local attacker to execute arbitrary code as root.

II. Impact

A user with local access can execute arbitrary code with root privileges.

III. Solution

Apply a patch from your vendor.

Sun patches:

108949-04: CDE 1.4: libDtHelp/libDtSvc patch
108950-04: CDE 1.4_x86: litDtHelp/libDtSvc patch


Please see other vendor statements for additional patch information.

Workaround

Disable dtprintinfo or 'chmod -s' the binary.

Systems Affected

VendorStatusDate Updated
Compaq Computer CorporationVulnerable30-Apr-2002
CrayNot Vulnerable20-Dec-2001
Hewlett PackardVulnerable22-Aug-2001
IBMVulnerable19-Dec-2001
Open GroupVulnerable17-Dec-2001
SGIUnknown17-Dec-2001
SunVulnerable5-Mar-2001
Xi GraphicsUnknown17-Dec-2001

References


http://www.opengroup.org/cde/
http://www.opengroup.org/desktop/faq/
http://www.eSecurityOnline.com/advisories/eSO2406.asp
http://www.iss.net/security_center/static/8034.php

Credit

The CERT/CC thanks Kevin Kotas of Ernst & Young's eSecurityOnline for reporting this vulnerability to us and to affected vendors.

This document was written by Jeffrey S. Havrilla.

Other Information

Date Public08/17/2001
Date First Published12/20/2001 02:00:12 PM
Date Last Updated04/30/2002
CERT Advisory 
CVE NameCAN-2001-0551
US-CERT Technical Alerts 
Metric6.75
Document Revision14

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2001 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader