PT-2003-2530 · Debian+3 · Debian+3
Claes Nyberg
+1
·
Published
1970-01-01
·
Updated
2017-07-11
·
CVE-2003-0144
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
lprold lpr package versions 7.1 through 7.3
OpenBSD versions 3.2 and earlier
Debian GNU/Linux (affected versions not specified)
lpr-ppd package (affected versions not specified)
Description
The issue allows local users to gain root privileges via long command line arguments, such as request ID or user name, potentially leading to disruption of confidentiality, integrity, and availability of protected information. The exploitation can be carried out by a local attacker.
Recommendations
For lprold lpr package versions 7.1 through 7.3, consider disabling the lprm command until a patch is available.
For OpenBSD versions 3.2 and earlier, restrict access to the lprm command to minimize the risk of exploitation.
For Debian GNU/Linux and lpr-ppd package, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Openbsd
Lpr-Ppd
Lprold Lpr