| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.11406 |
| Kategorie: | Gain root remotely |
| Titel: | Buffer overflow in BSD in.lpd |
| Zusammenfassung: | Determines if the remote lpd is bsd-lpd |
| Beschreibung: | The remote bsd-lpd daemon might be vulnerable to a buffer overflow when sent a too long file name and then asked to show the print queue when the file is being printed. An attacker may use this flaw to gain a shell on this host. ** Because of the conditions to positively check for ** this flaw are very hard to meet, this alert might be ** a false positive. Affected systems : BSD/OS (up to 4.1), FreeBSD (up to 4.2), NetBSD (up to 1.5.1), OpenBSD (up to 2.9), SuSE Linux (up to 7.2), SCO Open Server (5.0.6) Solution : Make sure you are running the latest version of the BSD line printer daemon Risk factor : High |
| Querverweis: |
BugTraq ID: 3252 Common Vulnerability Exposure (CVE) ID: CVE-2001-0670 ISS Security Advisory: 20010829 Remote Buffer Overflow Vulnerability in BSD Line Printer Daemon http://xforce.iss.net/alerts/advise94.php http://www.cert.org/advisories/CA-2001-30.html OpenBSD Security Advisory: 20010829 http://www.openbsd.com/errata28.html Caldera Security Advisory: CSSA-2001-SCO.20 ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.20/CSSA-2001-SCO.20.txt NETBSD Security Advisory: NetBSD-SA2001-018 ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-018.txt.asc http://www.redhat.com/support/errata/RHSA-2001-147.html CERT/CC vulnerability note: VU#274043 http://www.kb.cert.org/vuls/id/274043 XForce ISS Database: bsd-lpd-bo(7046) http://xforce.iss.net/static/7046.php http://www.securityfocus.com/bid/3252 Common Vulnerability Exposure (CVE) ID: CVE-1999-0061 NAI Labs Security Advisory: NAI-20 XForce ISS Database: bsd-lpd |
| Copyright | This script is Copyright (C) 2003 Renaud Deraison |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|