Solaris lpset Buffer Overflow...

- AV AC AU C I A
发布: 1999-05-11
修订: 2018-10-17

A stack buffer overflow vulnerability in the handling of the "-a" command in the lpset program allows arbitrary execution of code with root privileges. The lpset utility sets printing configuration information in the system configuration databases. lpset can be used to create and update printing configuration in /etc/printers.conf or Federated Naming System (FNS). Only a superuser or a member of Group 14 may execute lpset. There has been mixed results as to whether the applications exits with the message "Permission denied: not in group 14." before the overflow can be exploited, and thus the vulnerability can only be exploited by members of group 14.

0%
当前有1条漏洞利用/PoC
产品及版本信息(CPE)暂不可用