search menu icon-carat-right cmu-wordmark

CERT Coordination Center

CDE dtprintinfo contains local buffer overflow in Help window via clipboard copy

Vulnerability Note VU#860296

Original Release Date: 2001-12-20 | Last Revised: 2002-04-30

Overview

The CDE Print Viewer program dtprintinfo provides a graphical interface display the status of print queues and print jobs. By using the clipboard to overflow the search field in the Help window of dtprintinfo, a local attacker can execute arbitrary code on the system as root.

Description

There is a buffer overflow in the graphical program used to view print job status in CDE-aware desktop environments. Since dtprintinfo is commonly set to be setuid root, this defect could allow a local attacker to execute arbitrary code as root.

Impact

A user with local access can execute arbitrary code with root privileges.

Solution

Apply a patch from your vendor.

Sun patches:

108949-04: CDE 1.4: libDtHelp/libDtSvc patch
108950-04: CDE 1.4_x86: litDtHelp/libDtSvc patch


Please see other vendor statements for additional patch information.

Workaround

Disable dtprintinfo or 'chmod -s' the binary.

Vendor Information

860296
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

The CERT/CC thanks Kevin Kotas of Ernst & Young's eSecurityOnline for reporting this vulnerability to us and to affected vendors.

This document was written by Jeffrey S. Havrilla.

Other Information

CVE IDs: CVE-2001-0551
Severity Metric: 6.75
Date Public: 2001-08-17
Date First Published: 2001-12-20
Date Last Updated: 2002-04-30 18:42 UTC
Document Revision: 15

Sponsored by CISA.