Vulnerabilities in lpsched(1M) May Allow an Unprivileged User to Remove System Files or Disable the LP Service



Category :Security
Release Phase :Resolved
Product :Solaris 9 Operating System
Solaris 10 Operating System
Solaris 8 Operating System  
Bug Id :6314243, 6314245  
Date of Resolved Release :13-JAN-2006 


Impact

Security vulnerabilities in lpsched(1M) may allow a local unprivileged user the ability to delete any file or disable the LP print service on a system configured as a print server.

Sun acknowledges, with thanks, Hiroshi Nakano of Ryukoku University for bringing these issues to our attention.


Contributing Factors

These issues can occur in the following releases:

SPARC Platform

x86 Platform

Note: Solaris 7 will not be evaluated regarding the potential impact of the issue described in this Sun Alert.

This issue only affects systems which have been configured to act as print servers. To determine if the system has been configured as a print server, the following command can be used: 

    $ ls /etc/lp/printers

If there are files listed, then the host in question is a print server.


Symptoms

There are a number of possible symptoms of this issue, including the modification/deletion of files owned by privileged users and the disabling of the main Solaris print daemon. In order to check whether the Solaris print daemon has been disabled on a print server, the following command can be run:

    % lpstat -r

and will return either "scheduler is running" or "scheduler is not running."


Workaround

There is no workaround to these issues. Please see the Resolution section below.


Resolution

These issues are addressed in the following releases:

SPARC Platform

x86 Platform






Attachments
This solution has no attachment

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 200212
Article Type : Sun Alert
Last reviewed : 2006-04-24
Audience : PUBLIC
Keywords :
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article