← Back

CVE-2000-1220

nvd nist
Published: Jan 8, 2000Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.

Affected (32)

Products: Sgi: Irix · Redhat: Linux
1 product
Irix
1 product
Linux
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Sgi
Version 6.5.10
Version 6.5.11
Version 6.5.12
Version 6.5.13
Version 6.5.14f
Version 6.5.14m
Version 6.5.15f
Version 6.5.15m
Version 6.5.16f
Version 6.5.16m
Version 6.5.17f
Version 6.5.17m
Version 6.5.18f
Version 6.5.18m
Version 6.5.1
Version 6.5.2
Version 6.5.3
Version 6.5.4
Version 6.5.5
Version 6.5.6
Version 6.5.7
Version 6.5.8
Version 6.5.9
Version 6.5
Configuration B
8 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 4.0
Version 4.1
Version 4.2
Version 5.0
Version 5.1
Version 5.2
Version 6.0
Version 6.1

References (18)

ftp://patches.sgi.com/support/free/security/advisories/20021104-01-P (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
US Government Resource
ftp://patches.sgi.com/support/free/security/advisories/20021104-01-P (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.