Bug 19509

Summary: lpr: another local root compromise
Product: [Retired] Red Hat Linux Reporter: Chris Evans <chris>
Component: lprAssignee: Crutcher Dunnavant <crutcher>
Status: CLOSED NOTABUG QA Contact: David Lawrence <dkl>
Severity: medium Docs Contact:
Priority: medium    
Version: 6.2CC: notting
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://crash.ihug.co.nz/~Sneuro/lpd-adv.txt
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2000-10-21 16:05:45 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Chris Evans 2000-10-21 16:05:40 UTC
See the URL.
Alternatively, see the Bugtraq post in which this was recently reported:
http://www.securityfocus.com/archive/1/140614

This also illustrates the hazards of
1) Binaries not owned by root
2) Re-use of the same uid for different purposes/subsystems

Comment 1 Crutcher Dunnavant 2000-10-23 15:47:19 UTC
This was fixed in an old groff update for 6x and 5x,
get the latest updates, install, and this is gone.