A local buffer overflow exists in Network Instrument's NIPrint V4.10 (and possibly earlier versions). NIPrint v4.10 fails to verify input properly resulting in a buffer overflow, by sending 60 bytes of data to port 515/tcp. This could potentially be exploited to execute arbitrary code on the vulnerable system.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Public,
Exploit Commercial
Technical
NIPrint is a printing utility that provides LPD/LPR print services for connecting Unix and Microsoft Windows servers.
Solution
Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround(s):
Restrict access to the LPD service so that only trusted adresses can connect to it. Do not install NIPrint on systems with untrusted users.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.