Nessus Plugin #15122

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[DSA285] DSA-285-1 lprng

Family:
Debian Local Security Checks
Category:
infos
Copyright:
This script is (C) 2004 Michel Arboi
Summary:
DSA-285-1 lprng
Version:
$Revision: 1.4 $
Cve_id:
CAN-2003-0136
Bugtraq_id:
7334
Xrefs:
DSA:285
Description:

Karol Lewandowski discovered that psbanner, a printer filter that
creates a PostScript format banner and is part of LPRng, insecurely
creates a temporary file for debugging purpose when it is configured
as filter. The program does not check whether this file already
exists or is linked to another place, psbanner writes its current environment
and called arguments to the file unconditionally with the user id
daemon.
For the stable distribution (woody) this problem has been fixed in
version 3.8.10-1.2.
The old stable distribution (potato) is not affected by this problem.
For the unstable distribution (sid) this problem has been fixed in
version 3.8.20-4.
We recommend that you upgrade your lprng package.


Solution : http://www.debian.org/security/2003/dsa-285
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.