← Back

CVE-2000-1221

nvd nist
Published: Jan 8, 2000Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.

Affected (31)

Products: Sgi: Irix · Debian: Debian Linux · Redhat: Linux
1 product
Irix
1 product
Debian Linux
1 product
Linux
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Sgi
Version 6.5.10
Version 6.5.11
Version 6.5.12
Version 6.5.13
Version 6.5.14f
Version 6.5.14m
Version 6.5.15f
Version 6.5.15m
Version 6.5.16f
Version 6.5.16m
Version 6.5.17f
Version 6.5.17m
Version 6.5.18f
Version 6.5.18m
Version 6.5.1
Version 6.5.2
Version 6.5.3
Version 6.5.4
Version 6.5.5
Version 6.5.6
Version 6.5.7
Version 6.5.8
Version 6.5.9
Version 6.5
Configuration B
7 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.1
Redhat
Version 4.1
Version 4.2
Version 5.0
Version 5.2
Version 6.0
Version 6.1

References (16)

ftp://patches.sgi.com/support/free/security/advisories/20021104-01-P (unsafe URL)
Source: cve@mitre.org
Patch
Source: cve@mitre.org
US Government Resource
ftp://patches.sgi.com/support/free/security/advisories/20021104-01-P (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.