CVE-2000-1221
Summary
| CVE | CVE-2000-1221 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2000-01-08 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 2.1 | All | All | All |
| Operating System | Redhat | Linux | 4.1 | All | All | All |
| Operating System | Redhat | Linux | 4.2 | All | All | All |
| Operating System | Redhat | Linux | 5.0 | All | All | All |
| Operating System | Redhat | Linux | 5.2 | All | i386 | All |
| Operating System | Redhat | Linux | 6.0 | All | All | All |
| Operating System | Redhat | Linux | 6.1 | All | i386 | All |
| Operating System | Sgi | Irix | 6.5 | All | All | All |
| Operating System | Sgi | Irix | 6.5.1 | All | All | All |
| Operating System | Sgi | Irix | 6.5.10 | All | All | All |
| Operating System | Sgi | Irix | 6.5.11 | All | All | All |
| Operating System | Sgi | Irix | 6.5.12 | All | All | All |
| Operating System | Sgi | Irix | 6.5.13 | All | All | All |
| Operating System | Sgi | Irix | 6.5.14f | All | All | All |
| Operating System | Sgi | Irix | 6.5.14m | All | All | All |
| Operating System | Sgi | Irix | 6.5.15f | All | All | All |
| Operating System | Sgi | Irix | 6.5.15m | All | All | All |
| Operating System | Sgi | Irix | 6.5.16f | All | All | All |
| Operating System | Sgi | Irix | 6.5.16m | All | All | All |
| Operating System | Sgi | Irix | 6.5.17f | All | All | All |
| Operating System | Sgi | Irix | 6.5.17m | All | All | All |
| Operating System | Sgi | Irix | 6.5.18f | All | All | All |
| Operating System | Sgi | Irix | 6.5.18m | All | All | All |
| Operating System | Sgi | Irix | 6.5.2 | All | All | All |
| Operating System | Sgi | Irix | 6.5.3 | All | All | All |
| Operating System | Sgi | Irix | 6.5.4 | All | All | All |
| Operating System | Sgi | Irix | 6.5.5 | All | All | All |
| Operating System | Sgi | Irix | 6.5.6 | All | All | All |
| Operating System | Sgi | Irix | 6.5.7 | All | All | All |
| Operating System | Sgi | Irix | 6.5.8 | All | All | All |
| Operating System | Sgi | Irix | 6.5.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| patches.sgi.com/support/free/security/advisories/20021104-01-P | af854a3a-2127-422b-91ae-364da2661108 | patches.sgi.com | Patch |
| Multiple Vendor lpd Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Debian GNU/Linux -- Security Information -- lpr | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Patch |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| CERT/CC Vulnerability Note VU#30308 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| www.atstake.com/research/advisories/2000/lpd_advisory.txt | af854a3a-2127-422b-91ae-364da2661108 | www.atstake.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| The page cannot be found | af854a3a-2127-422b-91ae-364da2661108 | www.l0pht.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.