Required CVE Record Information
Description
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.
References 8 Total
- debian.org: 20000109 lpr -- access control problem and root exploit vendor-advisory
- atstake.com: A010800-v vendor-advisory
- securityfocus.com: 927 vdb-entry
- rhn.redhat.com: RHSA-2000:002 vendor-advisory
- kb.cert.org: VU#30308 third-party-advisory
- patches.sgi.com: 20021104-01-P vendor-advisory
- l0pht.com: 20000108 Quadruple Inverted Backflip vendor-advisory
- exchange.xforce.ibmcloud.com: redhat-lpd-auth(3840) vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 8 Total
- debian.org: 20000109 lpr -- access control problem and root exploit vendor-advisoryx_transferred
- atstake.com: A010800-v vendor-advisoryx_transferred
- securityfocus.com: 927 vdb-entryx_transferred
- rhn.redhat.com: RHSA-2000:002 vendor-advisoryx_transferred
- kb.cert.org: VU#30308 third-party-advisoryx_transferred
- patches.sgi.com: 20021104-01-P vendor-advisoryx_transferred
- l0pht.com: 20000108 Quadruple Inverted Backflip vendor-advisoryx_transferred
- exchange.xforce.ibmcloud.com: redhat-lpd-auth(3840) vdb-entryx_transferred