header-logo
Suggest Exploit
vendor:
OpenServer 5.0.6
by:
SecurityFocus
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: OpenServer 5.0.6
Affected Version From: SCO OpenServer 5.0.6
Affected Version To: SCO OpenServer 5.0.6
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002

SCO OpenServer 5.0.6 lpshut Buffer Overflow Vulnerability

SCO OpenServer 5.0.6 (and possibly earlier versions) ships with several suid bin executables used in printer administration and related tasks. This includes lpshut, a component used to shut down the LP print service. 'lpshut' contains a locally exploitable bufffer overflow due to a lack of bounds checking during operations performed on user-supplied data. An attacker may exploit this vulnerability to execute arbitrary code with effective userid 'bin' privileges.

Mitigation:

Upgrade to the latest version of SCO OpenServer 5.0.6 or later.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/2555/info


SCO OpenServer 5.0.6 (and possibly earlier versions) ships with several suid bin executables used in printer administration and related tasks.

This includes lpshut, a component used to shut down the LP print service. 'lpshut' contains a locally exploitable bufffer overflow due to a lack of bounds checking during operations performed on user-supplied data.

An attacker may exploit this vulnerability to execute arbitrary code with effective userid 'bin' privileges. 

/opt/K/SCO/Unix/5.0.6Ga/usr/lib/lpshut `perl -e 'print "A" x 7000'`

Memory fault - core dumped