Detailslpr has a format string security bug. It also mishandles any extension to The old BSD-based lpr which we shipped with Red Hat Linux 5.x and 6.x has a SolutionFor each RPM for your particular architecture, run:
rpm -Fvh [filename] where filename is the name of the RPM. Additionally, after upgrading, you will want to restart your "lpd" service by executing the following as root: /etc/rc.d/init.d/lpd restart If you do not need printing at all on your system, we recommend you remove the lpr print system: /etc/rc.d/init.d/lpd stop rpm -e lpr Updated packages
Bugs fixed (see bugzilla for more information)16725 - BSD lpr 0.50-5 Errata Tracking Bug References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1208
Thanks go to Chris Evans <chris@scary.beasts.org> for spotting this in the OpenBSD lpr CVS commit logs, and verifying the problem existed for Linux as well. Keywords
LPRng
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from: https://www.redhat.com/security/team/key/#package The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/ |
||||||||||||||||||||||||||||||||||||||||