CVE-2000-1220
Summary
| CVE | CVE-2000-1220 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2000-01-08 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Linux | 4.0 | All | All | All |
| Operating System | Redhat | Linux | 4.1 | All | All | All |
| Operating System | Redhat | Linux | 4.2 | All | All | All |
| Operating System | Redhat | Linux | 5.0 | All | All | All |
| Operating System | Redhat | Linux | 5.1 | All | All | All |
| Operating System | Redhat | Linux | 5.2 | All | i386 | All |
| Operating System | Redhat | Linux | 6.0 | All | All | All |
| Operating System | Redhat | Linux | 6.1 | All | i386 | All |
| Operating System | Sgi | Irix | 6.5 | All | All | All |
| Operating System | Sgi | Irix | 6.5.1 | All | All | All |
| Operating System | Sgi | Irix | 6.5.10 | All | All | All |
| Operating System | Sgi | Irix | 6.5.11 | All | All | All |
| Operating System | Sgi | Irix | 6.5.12 | All | All | All |
| Operating System | Sgi | Irix | 6.5.13 | All | All | All |
| Operating System | Sgi | Irix | 6.5.14f | All | All | All |
| Operating System | Sgi | Irix | 6.5.14m | All | All | All |
| Operating System | Sgi | Irix | 6.5.15f | All | All | All |
| Operating System | Sgi | Irix | 6.5.15m | All | All | All |
| Operating System | Sgi | Irix | 6.5.16f | All | All | All |
| Operating System | Sgi | Irix | 6.5.16m | All | All | All |
| Operating System | Sgi | Irix | 6.5.17f | All | All | All |
| Operating System | Sgi | Irix | 6.5.17m | All | All | All |
| Operating System | Sgi | Irix | 6.5.18f | All | All | All |
| Operating System | Sgi | Irix | 6.5.18m | All | All | All |
| Operating System | Sgi | Irix | 6.5.2 | All | All | All |
| Operating System | Sgi | Irix | 6.5.3 | All | All | All |
| Operating System | Sgi | Irix | 6.5.4 | All | All | All |
| Operating System | Sgi | Irix | 6.5.5 | All | All | All |
| Operating System | Sgi | Irix | 6.5.6 | All | All | All |
| Operating System | Sgi | Irix | 6.5.7 | All | All | All |
| Operating System | Sgi | Irix | 6.5.8 | All | All | All |
| Operating System | Sgi | Irix | 6.5.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CERT/CC Vulnerability Note VU#39001 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| patches.sgi.com/support/free/security/advisories/20021104-01-P | af854a3a-2127-422b-91ae-364da2661108 | patches.sgi.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Multiple Vendor lpd Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Bugtraq: L0pht Advisory: LPD, RH 4.x,5.x,6.x | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Debian GNU/Linux -- Security Information -- lpr | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| www.atstake.com/research/advisories/2000/lpd_advisory.txt | af854a3a-2127-422b-91ae-364da2661108 | www.atstake.com | |
| The page cannot be found | af854a3a-2127-422b-91ae-364da2661108 | www.l0pht.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.