37935vdb entry
http://osvdb.org/37935 CVE-2007-5381
Cisco IOS 12.3 - 'LPD' Remote Buffer Overflow
Record summary
CVE-2007-5381 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to be printed, as demonstrated by a telnet session to the LPD from a source port other than 515.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCisco IOS 12.3 - 'LPD' Remote Buffer OverflowExploitDB exploitby Andy DavisNot analyzed1 file
References
1027169Third-party advisory
http://secunia.com/advisories/27169 20071010 Cisco IOS Line Printer Daemon (LPD) Protocol Stack OverflowVendor advisory
http://www.cisco.com/en/US/products/products_security_response09186a00808d72e3.html irmplc.com
http://www.irmplc.com/index.php/155-Advisory-024 VU#230505Third-party advisory
http://www.kb.cert.org/vuls/id/230505 26001vdb entry
http://www.securityfocus.com/bid/26001 1018798vdb entry
http://www.securitytracker.com/id?1018798 ADV-2007-3457vdb entry
http://www.vupen.com/english/advisories/2007/3457 cisco-ios-lpd-bo(37046)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/37046 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-5381