PT-2003-2530 · Debian+3 · Debian+3
Claes Nyberg
+1
·
Publicado
1970-01-01
·
Atualizado
2017-07-11
·
CVE-2003-0144
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
lprold lpr package versions 7.1 through 7.3
OpenBSD versions 3.2 and earlier
Debian GNU/Linux (affected versions not specified)
lpr-ppd package (affected versions not specified)
Description
The issue allows local users to gain root privileges via long command line arguments, such as request ID or user name, potentially leading to disruption of confidentiality, integrity, and availability of protected information. The exploitation can be carried out by a local attacker.
Recommendations
For lprold lpr package versions 7.1 through 7.3, consider disabling the lprm command until a patch is available.
For OpenBSD versions 3.2 and earlier, restrict access to the lprm command to minimize the risk of exploitation.
For Debian GNU/Linux and lpr-ppd package, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Debian
Openbsd
Lpr-Ppd
Lprold Lpr