Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [NEWS] Multiple Vendor CUPS CGI Heap Overflow Vulnerability |
|---|---|
| Date: | 19 Mar 2008 08:05:51 +0200 |
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com - - promotion The SecuriTeam alerts list - Free, Accurate, Independent. Get your security news from a reliable source. http://www.securiteam.com/mailinglist.html - - - - - - - - - Multiple Vendor CUPS CGI Heap Overflow Vulnerability ------------------------------------------------------------------------ SUMMARY The Common UNIX Printing System, more commonly referred to as <http://www.cups.org/> CUPS, "provides a standard printer interface for various Unix based operating systems". Remote exploitation of a heap based buffer overflow vulnerability in CUPS, as included in various vendors' operating system distributions, could allow an attacker to execute arbitrary code with the privileges of the affected service. DETAILS Vulnerable Systems: * CUPS version 1.3.5 CUPS listens on TCP port 631 for requests. This interface provides access to several CGI applications used to administer CUPS and provide information about print jobs. By passing a specially crafted request, an attacker can trigger a heap based buffer overflow. Analysis: Exploitation of this vulnerability results in the execution of arbitrary code with the privileges of the affected service. Depending on the underlying operating system and distribution, CUPS may run as the lp, daemon, or a different user. In order to exploit this vulnerability remotely, the targeted host must be sharing a printer(s) on the network. If a printer is not being shared, where CUPS only listens on the local interface, this vulnerability could only be used to elevate privileges locally. Workaround: Disabling printer sharing will prevent this vulnerability from being exploited remotely. However, local users will still be able to obtain the privileges of the CUPS service user. Vendor reponse: Apple Inc. has addressed this vulnerability within Security Update 2008-002. For more information, visit the following URL. <http://docs.info.apple.com/article.html?artnum=307562> http://docs.info.apple.com/article.html?artnum=307562 CVE Information: <http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0047> CVE-2008-0047 Disclosure Timeline: 02/26/2008 - Initial vendor notification 02/26/2008 - Initial vendor response 03/18/2008 - Coordinated public disclosure ADDITIONAL INFORMATION The information has been provided by <mailto:idlabs-advisories@idefense.com> iDefense Labs Security Advisories. The original article can be found at: <http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=674> http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=674 ======================================== This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com ==================== ==================== DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [NT] BootManage TFTPD Buffer Overflow, SecuriTeam |
|---|---|
| Next by Date: | [NT] Argon Client Management Services Directory Traversal, SecuriTeam |
| Previous by Thread: | [NT] BootManage TFTPD Buffer Overflow, SecuriTeam |
| Next by Thread: | [NT] Argon Client Management Services Directory Traversal, SecuriTeam |
| Indexes: | [Date] [Thread] [Top] [All Lists] |