Common Desktop Environment 2.3.0 dtprintinfo Privilege Escalation
Posted by deepcore on May 21, 2019 – 8:10 am
A buffer overflow in the DtPrinterAction::PrintActionExists() function in the Common Desktop Environment 2.3.0 and earlier, as used in Oracle Solaris 10 1/13 (Update 11) and earlier, allows local users to gain root privileges via a long printer name passed to dtprintinfo by a malicious lpstat program.
Post a reply
You must be logged in to post a comment.