3.6
CVSSv2

CVE-2000-0880

Published: 14/11/2000 Updated: 19/12/2017
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 365
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program to kill the process that was specified in the lpdprocess file.

Vulnerable Product Search on Vulmon Subscribe to Product

plus technologies lpplus 3.2.2

plus technologies lpplus 3.3

Exploits

source: wwwsecurityfocuscom/bid/1643/info Vulnerability #1: Several files that are part of the LPPlus print management system are installed setuid root by default These files include: $LPHOME/bin/dccsched $LPHOME/bin/dcclpdser $LPHOME/bin/dccbkst These start the scheduler, LPD server and network status daemons $LPHOME/bin/dccshut ...