20030305 potential buffer overflow in lprm (fwd)mailing list
http://marc.info/?l=bugtraq&m=104690434504429&w=2 CVE-2003-0144
BSD 'lpr' 2000.05.07/0.48/0.72 / lpr-ppd 0.72 - Local Buffer Overflow (1)
Record summary
CVE-2003-0144 has a selected CVSS score of 7.2; EIP currently links 2 catalogued exploits.
Description
Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBBSD 'lpr' 2000.05.07/0.48/0.72 / lpr-ppd 0.72 - Local Buffer Overflow (1)ExploitDB exploitby Niall SmartNot analyzed1 file
ExploitDBBSD 'lpr' 2000.05.07/0.48/0.72 / lpr-ppd 0.72 - Local Buffer Overflow (2)ExploitDB exploitby CMNNot analyzed1 file
References
1020030308 OpenBSD lprm(1) exploitmailing list
http://marc.info/?l=bugtraq&m=104714441925019&w=2 8293Third-party advisory
http://secunia.com/advisories/8293 DSA-267Vendor advisory
http://www.debian.org/security/2003/dsa-267 DSA-275Vendor advisory
http://www.debian.org/security/2003/dsa-275 MDKSA-2003:059Vendor advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2003:059 SuSE-SA:2003:0014Vendor advisory
http://www.novell.com/linux/security/advisories/2003_014_lprold.html 7025vdb entry
http://www.securityfocus.com/bid/7025 lprm-bo(11473)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/11473 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0144