Title: LPRng Failure To Drop Supplementary Groups Vulnerability
Severity: MODERATE
Description:
The LPRng software is an enhanced, extended, and portable implementation of the Berkeley LPR print spooler functionality.
When the LPRng daemon is initialized, it drops its user id and group id but fails to drop the supplementary groups inherited from its parent process. As a result, the daemon and any child processes that it spawns will maintain the supplementary groups inherited from the process that started LPRng.
Processes or routines which are meant to be run with lowered privileges will run with these supplementary group privileges. Vulnerable sections of program code are often run with lowered privileges because of susceptibility to attacks. Because they are not dropped, these privileges may be gained by an attacker if LPRng is vulnerable to such attacks.
This vulnerability is related to BID 2974.
Affected Products:
- Patrick Powell LPRng 3.6.1
- Patrick Powell LPRng 3.6.10
- Patrick Powell LPRng 3.6.11
- Patrick Powell LPRng 3.6.12
- Patrick Powell LPRng 3.6.13
- Patrick Powell LPRng 3.6.14
- Patrick Powell LPRng 3.6.15
- Patrick Powell LPRng 3.6.16
- Patrick Powell LPRng 3.6.17
- Patrick Powell LPRng 3.6.18
- Patrick Powell LPRng 3.6.19
- Patrick Powell LPRng 3.6.2
- Patrick Powell LPRng 3.6.20
- Patrick Powell LPRng 3.6.3
- Patrick Powell LPRng 3.6.4
- Patrick Powell LPRng 3.6.5
- Patrick Powell LPRng 3.6.6
- Patrick Powell LPRng 3.6.7
- Patrick Powell LPRng 3.6.8
- Patrick Powell LPRng 3.6.9
- Patrick Powell LPRng 3.7.4
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.