20010827 LPRng/rhs-printfilters - remote execution of commandsmailing list
http://marc.info/?l=bugtraq&m=99892644616749&w=2 CVE-2001-1002
RedHat 6.2/7.0/7.1 Lpd - Remote Command Execution via DVI Printfilter Configuration Error
Record summary
CVE-2001-1002 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remote attackers to gain privileges by printing a DVI file that contains malicious commands.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBRedHat 6.2/7.0/7.1 Lpd - Remote Command Execution via DVI Printfilter Configuration ErrorExploitDB exploitby zenith parsecNot analyzed1 file
References
5RHSA-2001:102Vendor advisory
http://www.redhat.com/support/errata/RHSA-2001-102.html 3241vdb entry
http://www.securityfocus.com/bid/3241 dvips-lpd-command-execution(16509)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16509 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-1002