Debian: lpr buffer overflow vulnerability

    Date16 Apr 2003
    CategoryDebian
    2276
    Posted ByLinuxSecurity Advisories
    The correction for CAN-2003-0144 for the old stable distribution (potato) was a little bit too strict apparently and this update corrects this.
    
    - --------------------------------------------------------------------------
    Debian Security Advisory DSA 267-2                     This email address is being protected from spambots. You need JavaScript enabled to view it. 
    http://www.debian.org/security/                             Martin Schulze
    April 15th, 2003                         http://www.debian.org/security/faq
    - --------------------------------------------------------------------------
    
    Package        : lpr
    Vulnerability  : buffer overflow
    Problem-Type   : local
    Debian-specific: no
    CVE Id         : CAN-2003-0144
    
    The correction for CAN-2003-0144 for the old stable distribution
    (potato) was a little bit too strict apparently and this update
    corrects this.  For completeness here is the advisory text:
    
       A buffer overflow has been discovered in lpr, a BSD lpr/lpd line
       printer spooling system.  This problem can be exploited by a local
       user to gain root privileges, even if the printer system is set up
       properly.
    
    For the stable distribution (woody) this problem has been fixed in
    version 2000.05.07-4.3.
    
    For the old stable distribution (potato) this problem has been fixed
    in version 0.48-1.2.
    
    For the stable distribution (sid) this problem has been fixed in
    version 2000.05.07-4.20.
    
    We recommend that you upgrade your lpr package immediately.
    
    
    Upgrade Instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 2.2 alias potato
    - ---------------------------------
    
      Source archives:
    
         http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.2.dsc
          Size/MD5 checksum:      533 f66736520a00e74d609a421afdc08100
         http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.2.diff.gz
          Size/MD5 checksum:     8949 18e106588274936d15c89e42ad518fb3
         http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48.orig.tar.gz
          Size/MD5 checksum:    75943 7b67555568e1c2d03aedbe66098a52a5
    
      Alpha architecture:
    
         http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.2_alpha.deb
          Size/MD5 checksum:   112834 0cece83c9dfe9faf9bb1f6453822c7bd
    
      ARM architecture:
    
         http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.2_arm.deb
          Size/MD5 checksum:    89230 d403908d35e4d7ce9642183b11fa4457
    
      Intel IA-32 architecture:
    
         http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.2_i386.deb
          Size/MD5 checksum:    86036 7c2d6c093621b62e8ed7b2fde9bc3296
    
      Motorola 680x0 architecture:
    
         http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.2_m68k.deb
          Size/MD5 checksum:    81994 f884f37a9056b3ab0967ac027a3563a5
    
      PowerPC architecture:
    
         http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.2_powerpc.deb
          Size/MD5 checksum:    91248 f75d16b597c2e1cd908f5d20afd3f16a
    
      Sun Sparc architecture:
    
         http://security.debian.org/pool/updates/main/l/lpr/lpr_0.48-1.2_sparc.deb
          Size/MD5 checksum:    97840 64fc8bdbdc927ae7df58e0aadd0a8f74
    
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb  http://security.debian.org/ stable/updates main
    For dpkg-ftp:  ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.
    Package info: `apt-cache show ' and  http://packages.debian.org/
    
    
    You are not authorised to post comments.

    Comments powered by CComment

    LinuxSecurity Poll

    What do you think of the articles on LinuxSecurity?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/24-what-do-you-think-of-the-quality-of-the-articles-on-linuxsecurity?task=poll.vote&format=json
    24
    radio
    [{"id":"87","title":"Excellent, don't change a thing!","votes":"22","type":"x","order":"1","pct":55,"resources":[]},{"id":"88","title":"Should be more technical","votes":"5","type":"x","order":"2","pct":12.5,"resources":[]},{"id":"89","title":"Should include more HOWTOs","votes":"13","type":"x","order":"3","pct":32.5,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.