CVE-2000-1221
published 2000-01-08CVE-2000-1221: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local…
PriorityP343critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
16.73%
96.7th percentile
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | lpr | < lpr 1:0.48-1 (bookworm) | lpr 1:0.48-1 (bookworm) |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2000-01-08·CVSS 10.0
CVE-2000-1221 [CRITICAL] security flaw
security flaw
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.
Debian
CVE-2000-1221: lpr - The line printer daemon (lpd) in the lpr package in multiple Linux operating sys...
vendor_debian·2000·CVSS 10.0
CVE-2000-1221 [CRITICAL] CVE-2000-1221: lpr - The line printer daemon (lpd) in the lpr package in multiple Linux operating sys...
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.
Scope: local
bookworm: resolved (fixed in 1:0.48-1)
bullseye: resolved (fixed in 1:0.48-1)
forky: resolved (fixed in 1:0.48-1)
sid: resolved (fixed in 1:0.48-1)
trixie: resolved (fixed in 1:0.48-1)
GHSA
GHSA-7g6p-865f-j3r5: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the l
ghsa_unreviewed·2022-05-03
CVE-2000-1221 [HIGH] GHSA-7g6p-865f-j3r5: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the l
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.
OSV
CVE-2000-1221: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the l
osv·2000-01-08·CVSS 10.0
CVE-2000-1221 [CRITICAL] CVE-2000-1221: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the l
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.
No detection rules found.
Exploit-DB
Microsoft Active Movie Control 1.0 - Filetype
exploitdb·2000-05-13
CVE-2000-0400 Microsoft Active Movie Control 1.0 - Filetype
Microsoft Active Movie Control 1.0 - Filetype
---
source: https://www.securityfocus.com/bid/1221/info
The Microsoft Active Movie Control (a multimedia ActiveX control) will download files of any type specified in the control parameters in an HTML document, regardless of whether or not they are a valid media type. A hostile website, HTML email or HTML newsgroup post could therefore write executables and other potentially harmful content to target machines, which will be stored with their known filenames in the default Windows Temp directory.
This vulnerability could be used in conjunction with other exploits to run arbitrary code on the target machine(s).
The following script assumes a default Windows Temp folder of c:\windows\temp
Exploit-DB
RedHat 6.1 / IRIX 6.5.18 - 'lpd' Command Execution
exploitdb·2000-01-11
CVE-2000-1221 RedHat 6.1 / IRIX 6.5.18 - 'lpd' Command Execution
RedHat 6.1 / IRIX 6.5.18 - 'lpd' Command Execution
---
source: https://www.securityfocus.com/bid/927/info
Multiple vulnerabilities have been discovered in lpd, shipped with various Linux and Unix distributions.
It has been reported that lpd fails to properly authenticate hostnames. This could allow an unauthenticated user to gain access to lpd services by supplying a spoofed hostname.
It is also possible for a local user to pass arguments to sendmail, through the vulnerable print daemon. This could allow an unauthorized user to execute commands with elevated privileges.
By exploiting multiple vulnerabilities in lpd, it may be possible for a remote attacker to gain root privileges on a target server.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/197
ftp://patches.sgi.com/support/free/security/advisories/20021104-01-Phttp://rhn.redhat.com/errata/RHSA-2000-002.htmlhttp://www.atstake.com/research/advisories/2000/lpd_advisory.txthttp://www.debian.org/security/2000/20000109http://www.kb.cert.org/vuls/id/30308http://www.l0pht.com/advisories/lpd_advisoryhttp://www.securityfocus.com/bid/927https://exchange.xforce.ibmcloud.com/vulnerabilities/3840ftp://patches.sgi.com/support/free/security/advisories/20021104-01-Phttp://rhn.redhat.com/errata/RHSA-2000-002.htmlhttp://www.atstake.com/research/advisories/2000/lpd_advisory.txthttp://www.debian.org/security/2000/20000109http://www.kb.cert.org/vuls/id/30308http://www.l0pht.com/advisories/lpd_advisoryhttp://www.securityfocus.com/bid/927https://exchange.xforce.ibmcloud.com/vulnerabilities/3840
2000-01-08
Published