search menu icon-carat-right cmu-wordmark

CERT Coordination Center

IBM AIX line printer daemon contains a buffer overflow in kill_print()

Vulnerability Note VU#388183

Original Release Date: 2001-10-16 | Last Revised: 2002-01-03

Overview

The Line Printer daemon (lpd) shipped with AIX systems contains a buffer overflow in kill_print() that potentially allow a malicious remote user to gain root privileges.

Description

A buffer overflow exists in the kill_print() function of the line printer daemon (lpd) on AIX systems. An intruder could exploit this vulnerability to obtain root privileges or cause a denial of service (DoS). The intruder would need to be listed in the victim's /etc/hosts.lpd or /etc/hosts.equiv file, however, to exploit this vulnerability.

Impact

An intruder could exploit this vulnerability to obtain root privileges, or cause a denial of service (DoS).

Solution

IBM has released a VULNERABILITY SUMMARY. Please see the vendor statement for patches and instructions.

Vendor Information

388183
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

The CERT/CC wishes to thank IBM for their help in identifying and analyzing this vulnerability.

This document was written by Jason Rafail.

Other Information

CVE IDs: CVE-2001-0671
Severity Metric: 9.84
Date Public: 2001-09-11
Date First Published: 2001-10-16
Date Last Updated: 2002-01-03 19:09 UTC
Document Revision: 12

Sponsored by CISA.