Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2000-1220Redhat Linux vulnerability

11 documents8 sources
Severity
10.0CRITICALNVD
EPSS
3.1%
top 13.13%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 8
Latest updateMay 3

Description

The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDredhat/linux8 versions+7
NVDsgi/irix24 versions+23

🔴Vulnerability Details

3
GHSA
GHSA-7v4g-j9jw-cxjp: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to2022-05-03
CVEList
CVE-2000-1220: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to2005-04-21
OSV
CVE-2000-1220: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to2000-01-08

💥Exploits & PoCs

4
Exploit-DB
Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Local Buffer Overflow (2)2000-05-26
Exploit-DB
Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Remote Buffer Overflow (1)2000-05-16
Exploit-DB
Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Remote Buffer Overflow (3)2000-04-08
Exploit-DB
BSD / Linux - 'lpr' Local Privilege Escalation1996-10-25

📋Vendor Advisories

2
Red Hat
security flaw2000-01-08
Debian
CVE-2000-1220: lpr - The line printer daemon (lpd) in the lpr package in multiple Linux operating sys...2000

💬Community

1
Bugzilla
CVE-2000-1220 security flaw2018-08-16
CVE-2000-1220 — Redhat Linux vulnerability | cvebase