多厂商lpd远程缓冲区溢出漏洞

漏洞信息详情

多厂商lpd远程缓冲区溢出漏洞

漏洞简介

Solaris 8及其更早版本的line printer daemon (in.lpd)存在缓冲区溢出漏洞。远程攻击者可以借助“transfer job”例程获取根权限。

漏洞公告

Administrators are strongly advised to either apply network access control to the service or disable ‘in.lpd’. The daemon can be disabled by commenting out its associated line in ‘/etc/inetd.conf’ and re-starting inetd.
Patches are available.
Sun Solaris 8

  • Sun 109320-04

NetBSD NetBSD current pre20010805

IBM AIX 5.1

Sun Solaris 8_x86

  • Sun 109321-04

NetBSD NetBSD 1.4 x86

NetBSD NetBSD 1.4 Alpha

NetBSD NetBSD 1.4 SPARC

NetBSD NetBSD 1.4

NetBSD NetBSD 1.4 arm32

NetBSD NetBSD 1.4.1 Alpha

NetBSD NetBSD 1.4.1 arm32

NetBSD NetBSD 1.4.1 x86

NetBSD NetBSD 1.4.1

NetBSD NetBSD 1.4.1 SPARC

NetBSD NetBSD 1.4.1 sh3

NetBSD NetBSD 1.4.2

NetBSD NetBSD 1.4.2 x86

NetBSD NetBSD 1.4.2 arm32

NetBSD NetBSD 1.4.2 Alpha

NetBSD NetBSD 1.4.2 SPARC

NetBSD NetBSD 1.4.3

NetBSD NetBSD 1.5 x86

NetBSD NetBSD 1.5

NetBSD NetBSD 1.5 sh3

NetBSD NetBSD 1.5.1

NetBSD NetBSD 1.5.2

Sun Solaris 2.6 _x86

  • Sun 106236-09

Sun Solaris 2.6

  • Sun 106235-09

IBM AIX 4.3

SGI IRIX 6.5

SGI IRIX 6.5.1

SGI IRIX 6.5.10 f

SGI IRIX 6.5.10 m

参考网址

来源:CERT/CC Advisory: CA-2001-15
名称: CA-2001-15
链接:http://www.cert.org/advisories/CA-2001-15.html

来源: XF
名称: solaris-lpd-bo(6718)
链接:http://xforce.iss.net/static/6718.php

来源: ISS
名称: 20010619 Remote Buffer Overflow Vulnerability in Solaris Print Protocol Daemon
链接:http://xforce.iss.net/alerts/advise80.php

来源: BID
名称: 2894
链接:http://www.securityfocus.com/bid/2894

来源: SUN
名称: 00206
链接:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/206

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享