LPD: Metasploit Cascade Job Request

This signature detects attempts by Metasploit Vulnerability Framework to request a cascading job over LPD. This signature was written based on traffic from the Metasploit Framework.

Extended Description

The print protocol daemon, 'in.lpd' (or 'lpd'), shipped with Solaris may allow for remote attackers to execute arbitrary commands on target hosts with superuser privileges. The alleged vulnerability is not the buffer overflow discovered by ISS. It has been reported that it is possible to execute commands on target hosts through lpd by manipulating the use of sendmail by the daemon. If this vulnerability is successfully exploited, remote attackers can execute any command on the target host with superuser privileges. This vulnerability is very similar to one mentioned in NAI advisory NAI-0020. NOTE: It has been reported that a valid printer does NOT need to be configured to exploit this vulnerability.

Affected Products

Sun solaris

References

BugTraq: 3274

CVE: CVE-2001-1583

Short Name
LPD:MSF-CASCADE-JOB-REQ
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
LPD
Keywords
CVE-2001-1583 Cascade Job Metasploit Request bid:3274
Release Date
04/28/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Sun

CVSS Score

10.0

Found a potential security threat?