Bugtraq mailing list archives

Re: Linux & BSD's lpr exploit


From: security () ieee udistrital edu co (UDNet Security)
Date: Fri, 25 Oct 1996 13:33:30 -0500


lpr bug was tested in linux 2.1.5 kernel .... Distribution Slackware 96

This configuration is vulnerable.

ieee:security~# uname -a
Linux ieee 2.1.5 #3 Sat Oct 19 13:34:54 EST 1986 i486
ieee:security~# ./lpr
bash# id
uid=(503)security gid=100(users) euid=0(root) egid=7(lp) groups=100(users)
bash#



Workaraound:
I do a chmod -s /usr/bin/lpr .. it works fine, but then users cannot
print;

The patch works fine too.


Gustavo Lozano.



Current thread: