search menu icon-carat-right cmu-wordmark

CERT Coordination Center

IBM AIX line printer daemon contains a buffer overflow in chk_fhost()

Vulnerability Note VU#466239

Original Release Date: 2001-10-16 | Last Revised: 2002-01-03

Overview

The Line Printer daemon (lpd) shipped with AIX systems contains a buffer overflow in chk_fhost() that potentially allow a malicious remote user to gain root privileges.

Description

A buffer overflow exists in the chk_fhost() function of the line printer daemon (lpd) on AIX systems. An intruder could exploit this vulnerability to obtain root privileges or cause a denial of service (DoS). The intruder would need control of the DNS server to exploit this vulnerability.

Impact

An intruder could exploit this vulnerability to obtain root privileges, or cause a denial of service (DoS).

Solution

IBM has released a VULNERABILITY SUMMARY. Please see the vendor statement for patches and instructions.

Vendor Information

466239
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

The CERT/CC wishes to thank IBM for their help in identifying and analyzing this vulnerability.

This document was written by Jason Rafail.

Other Information

CVE IDs: CVE-2001-0671
Severity Metric: 9.84
Date Public: 2001-09-11
Date First Published: 2001-10-16
Date Last Updated: 2002-01-03 19:10 UTC
Document Revision: 8

Sponsored by CISA.