CVE-2001-0670

BSD < 4.1, FreeBSD < 4.3, NetBSD < 1.5.1, OpenBSD - Remote Code Execution via Incomplete Print Job

Title source: llm
STIX 2.1

Description

Buffer overflow in BSD line printer daemon (in.lpd or lpd) in various BSD-based operating systems allows remote attackers to execute arbitrary code via an incomplete print job followed by a request to display the printer queue.

References (9)

Core 9
Core References
US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-2001-30.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2001-147.html
Patch, Vendor Advisory third-party-advisory x_refsource_iss
http://xforce.iss.net/alerts/advise94.php
Vendor Advisory vendor-advisory x_refsource_netbsd
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-018.txt.asc
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3252
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/274043
Patch vendor-advisory x_refsource_openbsd
http://www.openbsd.com/errata28.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7046

Scores

EPSS 0.2070
EPSS Percentile 95.7%

Details

Status published
Products (4)
bsd/bsd < 4.1
freebsd/freebsd < 4.3
netbsd/netbsd < 1.5.1
openbsd/openbsd
Published Oct 03, 2001
Tracked Since Feb 18, 2026