7.2
CVSSv2

CVE-2003-0144

Published: 31/03/2003 Updated: 11/07/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 730
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 up to and including 7.3, OpenBSD 3.2 and previous versions, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.

Vulnerable Product Search on Vulmon Subscribe to Product

lprold lprold 3.0.48

freebsd freebsd 2.2.3

freebsd freebsd 2.2.4

openbsd openbsd 2.4

openbsd openbsd 2.5

freebsd freebsd 2.2.5

freebsd freebsd 2.2.6

openbsd openbsd 2.6

openbsd openbsd 2.7

freebsd freebsd 2.2

freebsd freebsd 2.2.2

openbsd openbsd 2.2

openbsd openbsd 2.3

openbsd openbsd 3.1

openbsd openbsd 3.2

bsd lpr 0.48

bsd lpr 2000-05-07

openbsd openbsd 2.0

openbsd openbsd 2.1

openbsd openbsd 2.8

openbsd openbsd 2.9

openbsd openbsd 3.0

Vendor Advisories

A buffer overflow has been discovered in lpr, a BSD lpr/lpd line printer spooling system This problem can be exploited by a local user to gain root privileges, even if the printer system is set up properly For the stable distribution (woody) this problem has been fixed in version 072-21 The old stable distribution (potato) does not contain lpr ...
A buffer overflow has been discovered in lpr, a BSD lpr/lpd line printer spooling system This problem can be exploited by a local user to gain root privileges, even if the printer system is set up properly For the stable distribution (woody) this problem has been fixed in version 20000507-43 For the old stable distribution (potato) this probl ...

Exploits

source: wwwsecurityfocuscom/bid/7025/info It has been reported that a vulnerability in the handling of some types of requests exists in lprm When an attacker sends a maliciously crafted string to a configured printer through the lprm command, it may be possible to execute code /* lprm-bsdc - Exploit for lprm vulnerability in ...
source: wwwsecurityfocuscom/bid/7025/info It has been reported that a vulnerability in the handling of some types of requests exists in lprm When an attacker sends a maliciously crafted string to a configured printer through the lprm command, it may be possible to execute code /* * lprmexpc * * OpenBSD <= 31 lprm(1) local root ...