CVE-2000-1220

SGI IRIX - Local Privilege Escalation via lpd sendmail Argument Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-1220. PoCs published by Vadim Kolontsov.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the `lpr` command (CVE-2000-1220) by crafting a malicious input that overflows the buffer in the `card()` function, leading to arbitrary code execution. The PoC includes shellcode to spawn a `/bin/sh` shell and is designed for both Linux and BSD systems.

Description

The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Vadim Kolontsov · clocallinux
https://www.exploit-db.com/exploits/325

This exploit targets a buffer overflow vulnerability in the `lpr` command (CVE-2000-1220) by crafting a malicious input that overflows the buffer in the `card()` function, leading to arbitrary code execution. The PoC includes shellcode to spawn a `/bin/sh` shell and is designed for both Linux and BSD systems.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: lpr (BSD and Linux versions)
No auth needed
Prerequisites: Access to execute the `lpr` command on the target system · Vulnerable version of `lpr` without the patch applied
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2000/20000109
Mailing List mailing-list x_refsource_bugtraq
http://seclists.org/lists/bugtraq/2000/Jan/0116.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/927
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/3841
Vendor Advisory vendor-advisory x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20021104-01-P
Various Sources vendor-advisory x_refsource_l0pht
http://www.l0pht.com/advisories/lpd_advisory
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/39001
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2000-002.html

Scores

EPSS 0.1422
EPSS Percentile 96.1%

Details

Status published
Products (32)
redhat/linux 4.0
redhat/linux 4.1
redhat/linux 4.2
redhat/linux 5.0
redhat/linux 5.1
redhat/linux 5.2
redhat/linux 6.0
redhat/linux 6.1
sgi/irix 6.5
sgi/irix 6.5.1
... and 22 more
Published Jan 08, 2000
Tracked Since Feb 18, 2026