vendor:
LPD
by:
Protek Research Lab
7,5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: LPD
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2009-0228
CPE: //a:lpd
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Windows
2009
LPD Buffer Overflow Exploit
This exploit is a proof-of-concept code for a buffer overflow vulnerability in the Line Printer Daemon (LPD) service. The vulnerability is triggered when a maliciously crafted print job is sent to the LPD service. The code sends a buffer of length 0x41 to the LPD service, which causes a buffer overflow and can lead to arbitrary code execution.
Mitigation:
Disable the LPD service if it is not needed. If it is needed, ensure that it is running the latest version of the software.