xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

LPRNG远程打印提交漏洞


发布时间:2002-06-13
更新时间:2002-06-13
严重程度:
威胁程度:其它
错误类型:配置错误
利用方式:服务器模式

BUGTRAQ ID:4980

受影响系统
Patrick Powell LPRng 3.7.4
   - HP Secure OS software for Linux 1.0
   - RedHat Linux 7.0
   - RedHat Linux 7.1
   - RedHat Linux 7.2
Patrick Powell LPRng 3.8.9
   - RedHat Linux 7.3
详细描述
LPRng是增强,扩展可移植的打印程序。

默认LPRng配置接收所有打印提交任务到打印队列,恶意攻击者可以提交许多打印请求到已经存在的打印队列。

测试代码


解决方案
下载程序:

Patrick Powell LPRng 3.7.4:

Red Hat RPM LPRng-3.7.4-23.1.src.rpm
ftp://updates.redhat.com/7.0/en/os/SRPMS/LPRng-3.7.4-23.1.src.rpm
Source RPM.

Red Hat RPM LPRng-3.7.4-23.1.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/LPRng-3.7.4-23.1.alpha.rpm
Red Hat Linux 7.0 Alpha.

Red Hat RPM LPRng-3.7.4-23.1.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/LPRng-3.7.4-23.1.i386.rpm
Red Hat Linux 7.0 i386.

Red Hat RPM LPRng-3.7.4-23.1.src.rpm
ftp://updates.redhat.com/7.1/en/os/SRPMS/LPRng-3.7.4-23.1.src.rpm
Red Hat Linux 7.1 source RPM.

Red Hat RPM LPRng-3.7.4-23.1.alpha.rpm
ftp://updates.redhat.com/7.1/en/os/alpha/LPRng-3.7.4-23.1.alpha.rpm
Red Hat Linux 7.1 Alpha.

Red Hat RPM LPRng-3.7.4-23.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/LPRng-3.7.4-23.1.i386.rpm
Red Hat Linux 7.1 i386.

Red Hat RPM LPRng-3.7.4-23.1.ia64.rpm
ftp://updates.redhat.com/7.1/en/os/ia64/LPRng-3.7.4-23.1.ia64.rpm
Red Hat Linux 7.1 ia64.

Red Hat RPM LPRng-3.7.4-28.1.src.rpm
ftp://updates.redhat.com/7.2/en/os/SRPMS/LPRng-3.7.4-28.1.src.rpm
Red Hat Linux 7.2 source RPM.

Red Hat RPM LPRng-3.7.4-28.1.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/LPRng-3.7.4-28.1.i386.rpm
Red Hat Linux 7.2 i386.

Red Hat RPM LPRng-3.7.4-28.1.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/LPRng-3.7.4-28.1.ia64.rpm
Red Hat Linux 7.2 ia64.

Patrick Powell LPRng 3.8.9:

Red Hat RPM LPRng-3.8.9-4.src.rpm
ftp://updates.redhat.com/7.3/en/os/SRPMS/LPRng-3.8.9-4.src.rpm
Red Hat Linux 7.3 source RPM.

Red Hat RPM LPRng-3.8.9-4.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/LPRng-3.8.9-4.i386.rpm
Red Hat Linux 7.3 i386.

相关信息
Matthew Caron
参考:http://online.securityfocus.com/advisories/4205
http://online.securityfocus.com/advisories/4198