cbcvebase.
CVE-2000-1220
published 2000-01-08

CVE-2000-1220: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute…

PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
14.22%
96.2th percentile
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlpr< lpr 1:0.48-1 (bookworm)lpr 1:0.48-1 (bookworm)
redhatlinux
redhatlinux
redhatlinux
redhatlinux
redhatlinux
redhatlinux
redhatlinux
redhatlinux
sgiirix
sgiirix
sgiirix
sgiirix
sgiirix
sgiirix
sgiirix
sgiirix
sgiirix
sgiirix
sgiirix
sgiirix
sgiirix
sgiirix
sgiirix
sgiirix

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.