vendor:
Linux
by:
SecurityFocus
7.5
CVSS
HIGH
Command Injection
78
CWE
Product Name: Linux
Affected Version From: RedHat Linux 6.2
Affected Version To: RedHat Linux 6.2
Patch Exists: YES
Related CWE: N/A
CPE: o:redhat:linux:6.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix
2002
lpr Vulnerability in RedHat Linux 6.2
The vulnerability is in the processing of troff files, their conversion into postscript files for printing on a postscript printer. When the processing occurs, certain commands embedded in the troff file being processed can be executed -- with the privileges of the setgid lpr. This is the result of formatting programs being executed by the print filter in an unsafe manner.
Mitigation:
Ensure that the lpr package is up to date and that all security patches have been applied.