Common Desktop Environment 2.3.0 dtprintinfo Privilege Escalation

A buffer overflow in the DtPrinterAction::PrintActionExists() function in the Common Desktop Environment 2.3.0 and earlier, as used in Oracle Solaris 10 1/13 (Update 11) and earlier, allows local users to gain root privileges via a long printer name passed to dtprintinfo by a malicious lpstat program.


MD5 | ea6e7c2d1a9b43266fe95e8a9d5cbc8a


Related Posts