Vulnerabilities > CVE-2003-0035 - Local Printer Name Buffer Overflow vulnerability in Robert Krawitz Escputil 1.15.2.2

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
robert-krawitz
nessus

Summary

Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.

Vulnerable Configurations

Part Description Count
Application
Robert_Krawitz
1

Nessus

NASL familyMandriva Local Security Checks
NASL idMANDRAKE_MDKSA-2003-010.NASL
descriptionKarol Wiesek and iDefense disovered three vulnerabilities in the printer-drivers package and tools it installs. These vulnerabilities allow a local attacker to empty or create any file on the filesystem. The first vulnerability is in the mtink binary, which has a buffer overflow in its handling of the HOME environment variable. The second vulnerability is in the escputil binary, which has a buffer overflow in the parsing of the --printer-name command line argument. This is only possible when esputil is suid or sgid; in Mandrake Linux 9.0 it was sgid
last seen2020-06-01
modified2020-06-02
plugin id13995
published2004-07-31
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/13995
titleMandrake Linux Security Advisory : printer-drivers (MDKSA-2003:010)