Executive Summary
Summary | |
---|---|
Title | New lprng packages fix insecure temporary file creation |
Informations | |||
---|---|---|---|
Name | DSA-285 | First vendor Publication | 2003-04-14 |
Vendor | Debian | Last vendor Modification | 2003-04-14 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 2.1 | Attack Range | Local |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Karol Lewandowski discovered that psbanner, a printer filter that creates a PostScript format banner and is part of LPRng, insecurely creates a temporary file for debugging purpose when it is configured as filter. The program does not check whether this file already exists or is linked to another place writes its current environment and called arguments to the file unconditionally with the user id daemon. For the stable distribution (woody) this problem has been fixed in version 3.8.10-1.2. The old stable distribution (potato) is not affected by this problem. For the unstable distribution (sid) these problems have been fixed in version 3.8.20-4. We recommend that you upgrade your lprng package. |
Original Source
Url : http://www.debian.org/security/2003/dsa-285 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:423 | |||
Oval ID: | oval:org.mitre.oval:def:423 | ||
Title: | LPRng Symbolic Link Attack Vulnerability | ||
Description: | psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2003-0136 | Version: | 4 |
Platform(s): | Red Hat Linux 9 | Product(s): | LPRng |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 4 |
OpenVAS Exploits
Date | Description |
---|---|
2008-01-17 | Name : Debian Security Advisory DSA 285-1 (lprng) File : nvt/deb_285_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
12641 | LPRng psbanner Symlink File Overwrite |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-09-29 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-285.nasl - Type : ACT_GATHER_INFO |
2004-07-31 | Name : The remote Mandrake Linux host is missing a security update. File : mandrake_MDKSA-2003-060.nasl - Type : ACT_GATHER_INFO |
2004-07-06 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2003-150.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:32:31 |
|