Published: 14/11/2000 Updated: 19/12/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.
Vulnerable Product Search on Vulmon Subscribe to Product


source: wwwsecurityfocuscom/bid/1644/info $LPHOME/bin/dccscan is suid-root and can be executed by any user It is possible for an unprivileged user to print files to which he does not have read access In testing, this works even for printers to which the user is is not given any access in the LPPlus security configuration # id uid=0(ro ...