Overview
The Cisco IOS Line Printer Daemon contains a buffer overflow vulnerability. If successfully exploited, this vulnerability may allow an attacker to execute arbitrary code or create a denial-of-service condition .
Description
The Cisco IOS includes support for the UNIX Line Printer Daemon (LPD) protocol. The LPD service listens on 515/tcp and is not enabled by default. The IOS LPD service does not properly check the length of the hostname of the router. This error may result in a buffer overflow. See Cisco Security Response Document ID: 99109 for more information about this vulnerability. |
Impact
An attacker may be able to execute arbitrary code or create a denial-of-service condition . |
Solution
Cisco has released an update to address this issue. See Cisco Security Response: Cisco IOS Line Printer Daemon (LPD) Protocol Stack Overflow Document ID: 99109 for more details. |
The following workarounds may mitigate this vulnerability.
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.cisco.com/warp/public/707/cisco-sr-20071010-lpd.shtml
- http://www.irmplc.com/index.php/155-Advisory-024
- http://www.cisco.com/univercd/cc/td/doc/product/software/ios120/120newft/120t/120t3/snmp3.htm#wp4390
- http://www.cisco.com/en/US/products/sw/iosswrel/ps1830/products_feature_guide09186a00800878fa.html#wp4363
- http://www.cisco.com/en/US/docs/ios/11_3/security/configuration/guide/scacls.html
Acknowledgements
Information about this vulnerability was released by Information Risk Management.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2007-5381 |
Severity Metric: | 7.14 |
Date Public: | 2007-10-10 |
Date First Published: | 2007-10-13 |
Date Last Updated: | 2007-10-15 17:09 UTC |
Document Revision: | 12 |