20000906 Multiple Security Holes in LPPlusmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-08/0531.html CVE-2000-0880
LPPlus 3.2.2/3.3 - Permissions Denial of Service
Record summary
CVE-2000-0880 has a selected CVSS score of 3.6; EIP currently links 1 catalogued exploit.
Description
LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program to kill the process that was specified in the lpdprocess file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLPPlus 3.2.2/3.3 - Permissions Denial of ServiceExploitDB exploitby Dixie FlatlineNot analyzed1 file
References
41643vdb entry
http://www.securityfocus.com/bid/1643 lpplus-process-perms-dos(5200)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5200 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0880