CVE-2000-1208Use of Externally-Controlled Format String in Immunix

5 documents5 sources
Severity
7.2HIGHNVD
EPSS
0.0%
top 85.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12
Latest updateApr 30

Description

Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages3 packages

Also affects: Netbsd 1.4, 1.4.1, 1.4.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x8pj-r335-vm92: Format string vulnerability in startprinting() function of printjob2022-04-30
CVEList
CVE-2000-1208: Format string vulnerability in startprinting() function of printjob2002-08-01

📋Vendor Advisories

1
Red Hat
security flaw2000-05-31

💬Community

1
Bugzilla
CVE-2000-1208 security flaw2018-08-16
CVE-2000-1208 — Immunix vulnerability | cvebase