PT-2001-1031 · Bsd · Lpr
Published
2001-10-03
·
Updated
2017-10-10
·
CVE-2001-0670
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
lpr version 0.50.5
Description
The issue is related to a buffer overflow in the BSD line printer daemon, which can be exploited remotely. This can lead to the execution of arbitrary code via an incomplete print job followed by a request to display the printer queue, potentially disrupting the confidentiality, integrity, and availability of protected information.
Recommendations
For lpr version 0.50.5, consider disabling the lpd daemon as a temporary workaround until a patch is available. Restrict access to the printer queue to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lpr