Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
87

Debian 2.2: DSA-267-2 Urgent: lpr Local Root Security Vulnerability

The correction for CAN-2003-0144 for the old stable distribution (potato) was a little bit too strict apparently and this update corrects this.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 267-2 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze April 15th, 2003 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : lpr Vulnerability : buffer overflow Problem-Type : local Debian-specific: no CVE Id : CAN-2003-0144 The correction for CAN-2003-0144 for the old stable distribution (potato) was a little bit too strict apparently and this update corrects this. For completeness here is the advisory text: A buffer overflow has been discovered in lpr, a BSD lpr/lpd line printer spooling system. This problem can be exploited by a local user to gain root privileges, even if the printer system is set up properly. For the stable distribution (woody) this problem has been fixed in version 2000.05.07-4.3. For the old stable distribution (potato) this problem has been fixed in version 0.48-1.2. For the stable distribution (sid) this problem has been fixed in version 2000.05.07-4.20. We recommend that you upgrade your lpr package immediately. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 2.2 alias potato - --------------------------------- Source archives: Size/MD5 checksum: 533 f66736520a00e74d609a421afdc08100 Size/MD5 checksum: 8949 18e106588274936d15c89e42ad518fb3 Size/MD5 checksum: 75943 7b67555568e1c2d03aedbe66098a52a5 Alpha architecture: Size/MD5 checksum: 112834 0cece83c9dfe9faf9bb1f6453822c7bd ARM architecture: Size/MD5 checksum: 89230 d403908d35e4d7ce9642183b11fa4457 Intel IA-32 architecture: Size/MD5 checksum: 86036 7c2d6c093621b62e8ed7b2fde9bc3296 Motorola 680x0 architecture: Size/MD5 checksum: 81994 f884f37a9056b3ab0967ac027a3563a5 PowerPC architecture: Size/MD5 checksum: 91248 f75d16b597c2e1cd908f5d20afd3f16a Sun Sparc architecture: Size/MD5 checksum: 97840 64fc8bdbdc927ae7df58e0aadd0a8f74 - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Urgent local root security issue in Debian lpr; critical buffer overflow vulnerability needs immediate attention.. Debian Buffer Overflow,lpr Upgrade,Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 16, 2003 Critical Debian
87

Debian: DSA-267-1 Urgent Advisory: Lpr Local Exploit Vulnerability

A buffer overflow has been discovered in lpr, a BSD lpr/lpd lineprinter spooling system.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 267-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze March 24th, 2003 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : lpr Vulnerability : buffer overflow Problem-Type : local Debian-specific: no CVE Id : CAN-2003-0144 A buffer overflow has been discovered in lpr, a BSD lpr/lpd line printer spooling system. This problem can be exploited by a local user to gain root privileges, even if the printer system is set up properly. For the stable distribution (woody) this problem has been fixed in version 2000.05.07-4.3. For the old stable distribution (potato) this problem has been fixed in version 0.48-1.1. For the stable distribution (sid) this problem has been fixed in version 2000.05.07-4.20. We recommend that you upgrade your lpr package immediately. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 2.2 alias potato - --------------------------------- Source archives: Size/MD5 checksum: 533 2eb50aa0c9f2292f2977d0029bd3fdd3 Size/MD5 checksum: 8800 709256e0ad0a7f664aba6e0c2ddaf231 Size/MD5 checksum: 75943 7b67555568e1c2d03aedbe66098a52a5 Alpha architecture: Size/MD5 checksum: 112682 1ea3231bfa2024cb1d7d9fd8c94aa091 ARM architecture: Size/MD5 checksum: 89128 d185b06412be87a1966ac25cda23dea1 Intel IA-32 architecture: Size/MD5 checksum: 85960 1758a9683ae487c20f46a73ba32d9c15 Motorola 680x0 architecture: Size/MD5 checksum: 81900 f64919ec85dd3bdc27d6f7de192fafc5 PowerPC architecture: Size/MD5 checksum: 91200 3b790c8221b61cf7aaff0bcb90fe00de Sun Sparc architecture: Size/MD5 checksum: 97776 954f64d74744f3c37fecbb4a78ffbe14 Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 559 8daab94fdff4f6e286224956eaecf054 Size/MD5 checksum: 24745 8e7a035f2392a1e4a43ab3eef20a596d Size/MD5 checksum: 71600 d0e726f0fea4324c9b63db50bbfd778e Alpha architecture: Size/MD5 checksum: 129660 94f6b0b445c3b89ce76f2e2d3fa54c6e ARM architecture: Size/MD5 checksum: 95384 31e43ac786a3731b7d19eee00b757adc Intel IA-32 architecture: Size/MD5 checksum: 93136 4d81cb964fb6bdcf732bbedcbf06ce45 Intel IA-64 architecture: Size/MD5 checksum: 158734 a58ce7dd66d423dbf26e3eb9e16dd5d4 HP Precision architecture: Size/MD5 checksum: 108290 1cabcb262997bdc0bea262b9a54c1392 Motorola 680x0 architecture: Size/MD5 checksum: 90322 aacd62143f4736ed6ac5d80f0399bb1c Big endian MIPS architecture: Size/MD5 checksum: 111904 2af9c7b4e0754ebf7e175e59a2a20574 Little endian MIPS architecture: Size/MD5 checksum: 111708 7fb650fb9c86835f68b774054f80434f PowerPC architecture: Size/MD5 checksum: 97256 a0a12802e5ec7a021f2d9cb932ca7191 IBM S/390 architecture: Size/MD5 checksum: 97214 08606777eeb7d98a11835030fe2298a6 Sun Sparc architecture: Size/MD5 checksum: 122218 2f870ec489eacb68628d9522a68ceb77 These files will probably be moved into the stable distribution on its next revision. ---------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . The Ubuntu security notice USN-1234-1 addresses a critical memory corruption issue in the ssh client, potentially enabling local users to obtain system administrator privileges. Buffer Overflow,Lpr Security,Debian Advisory,Local Exploit,System Upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 25, 2003 Critical Debian
98

RedHat 6.1: RHSA-2000:002-01 Critical: lpr Authentication Flaw

Authentication and configuration vulnerabilities that could lead to a root compromise exist.. Package lpr Synopsis New lpr packages available Advisory ID RHSA-2000:002-01 Issue Date 2000-01-07 Updated on 2000-01-07 Keywords lpr lpd DNS sendmail 1. Topic: New lpr packages are available to fix two security problems in lpd. 2. Problem description: Two security vulnerabilities exist in the lpd (line printer daemon) shipped with the lpr package. First, authentication was not thorough enough. If a remote user was able to control their own DNS so that their IP address resolved to the hostname of the print server, access would be granted, when it should not be. Secondly, it was possible in the control file of a print job to specify arguments to sendmail. By careful manipulation of control and data files, this could cause sendmail to be executed with a user-specified configuration file. This could lead very easily to a root compromise. It is recommended that all users of Red Hat Linux using the lpr package (which is required to print) upgrade to the fixed packages. Thanks go to DilDog (dildog@l0pht.com) for noting the vulnerability. If you are experiencing problems with local printing in Red Hat Linux 6.1, make sure that you have: alias parport_lowlevel parport_pc in your /etc/conf.modules file. 3. Bug IDs fixed: (see bugzilla for more information) 4. Relevant releases/architectures: Red Hat Linux 6.1, all architectures 5. Obsoleted by: None 6. Conflicts with: None 7. RPMs required: Intel: lpr-0.48-1.i386.rpm Alpha: lpr-0.48-1.alpha.rpm SPARC: lpr-0.48-1.sparc.rpm Source: lpr-0.48-1.src.rpm 8. Solution: For each RPM for your particular architecture, run: rpm-Uvh filename where filename is the name of the RPM. Then, restart lpd: /etc/rc.d/init.d/lpd restart 9. Verification: MD5 sum Package Name ------------------------------------------------------------------------- 78f2220331189e723eab944b53d0710e i386/lpr-0.48-1.i386.rpm 3fcb89eb1a76741a505d3eeeddfa3674 alpha/lpr-0.48-1.alpha.rpm 441cfee04428ca215d98d9ce3d20bc4d sparc/lpr-0.48-1.sparc.rpm 55c6a740b03569919ec08992257cad96 SRPMS/lpr-0.48-1.src.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: About You can verify each package with the following command: rpm --checksig filename If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg filename Note that you need RPM > = 3.0 to check GnuPG keys. 10. References: Thanks to This email address is being protected from spambots. You need JavaScript enabled to view it. for finding this bug. . Update lpr packages on RedHat to enhance security and mitigate vulnerabilities. Follow the secure setup steps for integrity.. RedHat Security,lpr patches,authentication issues,configuration vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 07, 2000 Critical Red Hat
98

Red Hat 6.x: RHSA-2000:002-01 Critical: Lpr Access Control Threat

New lpr packages are available to fix two security problems in lpd.. ` --------------------------------------------------------------------- Red Hat, Inc. Security Advisory Synopsis: New lpr packages available Advisory ID: RHSA-2000:002-01 Issue date: 2000-01-07 Updated on: 2000-01-07 Keywords: lpr lpd DNS sendmail Cross references: --------------------------------------------------------------------- 1. Topic: New lpr packages are available to fix two security problems in lpd. 2. Relevant releases/architectures: Red Hat Linux 4.x, all architectures Red Hat Linux 5.x, all architectures Red Hat Linux 6.x, all architectures 3. Problem description: Two security vulnerabilities exist in the lpd (line printer daemon) shipped with the lpr package. First, authentication was not thorough enough. If a remote user was able to control their own DNS so that their IP address resolved to the hostname of the print server, access would be granted, when it should not be. Secondly, it was possible in the control file of a print job to specify arguments to sendmail. By careful manipulation of control and data files, this could cause sendmail to be executed with a user-specified configuration file. This could lead very easily to a root compromise. It is recommended that all users of Red Hat Linux using the lpr package (which is required to print) upgrade to the fixed packages. Thanks go to DilDog (This email address is being protected from spambots. You need JavaScript enabled to view it.) for noting the vulnerability. 4. Solution: For each RPM for your particular architecture, run: rpm -Fvh where filename is the name of the RPM. 5. Bug IDs fixed ( for more info): 6. Obsoleted by: 7. Conflicts with: 8. RPMs required: Red Hat Linux 6.x: Intel: Alpha: Sparc: Source packages: Red Hat Linux 5.x: Intel: Alpha: Sparc: Source packages: Red Hat Linux 4.x: Intel: Alpha: Sparc: Source packages: 9. Verification: MD5 sum PackageName -------------------------------------------------------------------------- 78f2220331189e723eab944b53d0710e i386/lpr-0.48-1.i386.rpm 3fcb89eb1a76741a505d3eeeddfa3674 alpha/lpr-0.48-1.alpha.rpm 441cfee04428ca215d98d9ce3d20bc4d sparc/lpr-0.48-1.sparc.rpm 55c6a740b03569919ec08992257cad96 SRPMS/lpr-0.48-1.src.rpm 25ba4d2b49ff42403062d44f52f59947 i386/lpr-0.48-0.5.2.i386.rpm aa13284c581601705fef727565ed407e alpha/lpr-0.48-0.5.2.alpha.rpm 8d158ba104fadbfc84b5122f9564b2ed sparc/lpr-0.48-0.5.2.sparc.rpm 3d7a10a086f5bd5aea739ec41d761881 SRPMS/lpr-0.48-0.5.2.src.rpm a215955554df002e91e336abd310e3f1 i386/lpr-0.48-0.4.2.i386.rpm a96363769e3815a5a5bb40084d8fac61 alpha/lpr-0.48-0.4.2.alpha.rpm f56271b462851990238a24a5357c454f sparc/lpr-0.48-0.4.2.sparc.rpm 48453e0c888e3d124a6b50fbb9a89be9 SRPMS/lpr-0.48-0.4.2.src.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 10. References: `. New lpr enhancements have been released by Red Hat to address critical security flaws identified in the line printer daemon lpd.. Red Hat Linux,lpr package,security issues,line printer daemon,authentication flaw. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 11, 2000 Critical Red Hat
100

RedHat: 2000:102345 High: lprold File Access Permissions Exploit

The file access permissions aren't properly checked by the lpr and lpd program. . ______________________________________________________________________________ SuSE Security Announcement Package: lprold

Calendar 2 Dec 08, 1999 SuSE
98

Red Hat: RHSA-1999:041-03 Moderate: Lpr File Access Problem

There are potential problems with file access checking in the lpr and lpd programs. These could allow users to potentially print files they do not have access to. Also, there are bugs in remote printing in the lpd that shipped with Red Hat Linux 6.1. . Red Hat, Inc. Security Advisory Package lpr Synopsis File access problems in lpr/lpd Advisory ID RHSA-1999:041-03 Issue Date 1999-10-17 Updated on 1999-10-25 Keywords lpr lpd permissions Cross references N/A Revision History: 1999-10-25: New packages, to fix problems introduced by the security fix. 1999-10-19: New packages, to fix a remote printing bug. Add note about local printing fix for Red Hat Linux 6.1. 1. Topic: There are potential problems with file access checking in the lpr and lpd programs. These could allow users to potentially print files they do not have access to. Also, there are bugs in remote printing in the lpd that shipped with Red Hat Linux 6.1. 2. Problem description: There are two problems in the lpr and lpd programs. By exploiting a race between the access check and the actual file opening, it is potentially possible to have lpr read a file as root that the user does not have access to. Also, the lpd program would blindly open queue files as root; by use of the '-s' flag to lpr, it was possible to have lpd print files that the user could not access. Thanks go to Tymm Twillman for pointing out these vulnerabilities. (1999-10-19) Another problem with remote printing was fixed in lpr-0.44. If you are experiencing problems with remote printing in the previous errata update, it is recommended that you upgrade. There are no known security issues with the previous errata packages. If you are experiencing problems with local printingin Red Hat Linux 6.1, make sure that you have: alias parport_lowlevel parport_pc in your /etc/conf.modules file. (1999-10-25) The original security patch broke some aspects of printing. New errata RPMs are available which should fix the problem. 3. Bug IDs fixed: (see bugzilla for more information) 5122 5540 5697 5832 5835 5903 5949 4. Relevant releases/architectures: Red Hat Linux 6.1, all architectures 5. Obsoleted by: None 6. Conflicts with: None 7. RPMs required: Intel: lpr-0.46- 1.i386.rpm Alpha: lpr-0.46- 1.alpha.rpm SPARC: lpr-0.46- 1.sparc.rpm Source: lpr-0.46- 1.src.rpm Architecture neutral: 8. Solution: For each RPM for your particular architecture, run: rpm -Uvh filename where filename is the name of the RPM. 9. Verification: MD5 sum Package Name ------------------------------------------------------------------------- 03c996550636cbe4ca0a9fc853f969b6 lpr-0.46-1.src.rpm 30089f82ecf8e8a89565c5bba361697d lpr-0.46-1.alpha.rpm a01c0b9278c2c9ffb4bb6450703fc124 lpr-0.46-1.i386.rpm 41a1ef221a15446ed46b54092d7c14ca lpr-0.46-1.sparc.rpm These packages are GPG signed by Red Hat Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig filename If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg filename 10. References: . Concerns regarding file accessibility in lpr/lpd highlighted by Red Hat, crucial for safeguarding print functionalities. Bulletin RHSA-1999:041-03.. Red Hat Advisory, Lpr Security, File Access Issues, Remote Printing Flaws. . LinuxSecurity.com Team

Calendar 2 Dec 07, 1999 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here