![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.51253 |
Category: | Red Hat Local Security Checks |
Title: | RedHat Security Advisory RHSA-2002:120 |
Summary: | NOSUMMARY |
Description: | Description: The remote host is missing updates announced in advisory RHSA-2002:120. The LPRng print spooler, as shipped in Red Hat Linux Advanced Server 2.1, accepts all remote print jobs by default. Updated LPRng packages are available to fix this issue. With its default configuration, LPRng will accept job submissions from any host, which is not appropriate in a workstation environment. We are grateful to Matthew Caron for pointing out this configuration problem. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2002-0378 to this issue. The updated packages from this advisory change the job submission policy (in /etc/lpd.perms) so that jobs from remote hosts are refused by default. Those running print servers may want to adjust this policy as appropriate, for example to give access to certain hosts or subnets. For details on how to do this, see the lpd.perms(5) man page. Please note that default installations of Red Hat Linux Advanced Server 2.1 include ipchains rules blocking remote access to the print spooler IP port as a result those installations already reject remote job submissions. NOTE: There are special instructions for installing this update at the end of the 'Solution' section. Solution: Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date http://rhn.redhat.com/errata/RHSA-2002-120.html Risk factor : High CVSS Score: 7.5 |
Cross-Ref: |
BugTraq ID: 4980 Common Vulnerability Exposure (CVE) ID: CVE-2002-0378 http://www.securityfocus.com/bid/4980 HPdes Security Advisory: HPSBTL0206-048 http://online.securityfocus.com/advisories/4205 http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-042.php http://www.redhat.com/support/errata/RHSA-2002-089.html http://www.iss.net/security_center/static/9322.php |
Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |