|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
APS Filter Development Team apsfilter contains a flaw that when used on FreeBSD may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when apsfilter, which uses the lpd printing daemon with a setuid of root, insecurely reads filter configurations created by a malicious user. This flaw may lead to a loss of integrity.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Rumored / Private
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version the apsfilter package to version 5.4.2 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround: deinstall the apsfilter port/package.
|
|
Products |
|
apsfilter
 |
5.4 |
|
FreeBSD
 |
4.0 |
3.2 |
3.3 |
3.4 |
5.0 |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|