lpadmin in SCO OpenServer 5.0.6 can allow a local malicious user to gain additional privileges via a buffer overflow attack in the first argument to the command.
source: wwwsecurityfocuscom/bid/2553/info
SCO OpenServer 506 (and possibly earlier versions) ships with several suid 'bin' executables used in printer administration and related tasks
This includes lpadmin, a component used to manage and configure print destinations, devices and printer interface programs
'lpadmin' contains a locall ...