20000108 L0pht Advisory: LPD, RH 4.x,5.x,6.xmailing list
http://seclists.org/lists/bugtraq/2000/Jan/0116.html CVE-2000-1220
BSD / Linux - 'lpr' Local Privilege Escalation
Record summary
CVE-2000-1220 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBBSD / Linux - 'lpr' Local Privilege EscalationExploitDB exploitby Vadim KolontsovNot analyzed1 file
References
9atstake.com
http://www.atstake.com/research/advisories/2000/lpd_advisory.txt 20000109 lpr -- access control problem and root exploitVendor advisory
http://www.debian.org/security/2000/20000109 VU#39001Third-party advisory
http://www.kb.cert.org/vuls/id/39001 20000108 Quadruple Inverted BackflipVendor advisory
http://www.l0pht.com/advisories/lpd_advisory RHSA-2000:002Vendor advisory
http://www.redhat.com/support/errata/RHSA-2000-002.html 927vdb entry
http://www.securityfocus.com/bid/927 redhat-lpd-print-control(3841)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/3841 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-1220