Vulnerability Name:

CVE-1999-1102 (CCN-7209)

Assigned:1991-08-19
Published:1991-08-19
Updated:2008-09-05
Summary:lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
2.6 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:File Manipulation
References:Source: CCN
Type: CIAC Information Bulletin E-25a
BSD lpr Vulnerability in SGI IRIX

Source: CIAC
Type: Patch, Vendor Advisory
E-25a

Source: MITRE
Type: CNA
CVE-1999-1102

Source: BUGTRAQ
Type: UNKNOWN
19940307 8lgm Advisory Releases

Source: CCN
Type: 8lgm Advisory #03
[8lgm]-Advisory-3.UNIX.lpr.19-Aug-1991

Source: CCN
Type: OSVDB ID: 9020
Multiple Vendor lpr 1000x Symlink Arbitrary File Create/Overwrite

Source: MISC
Type: Exploit, Vendor Advisory
http://www.phreak.org/archives/security/8lgm/8lgm.lpr

Source: XF
Type: UNKNOWN
bsd-lpr-symlink(7209)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:sgi:irix:*:*:*:*:*:*:*:* (Version <= 5.2)

  • Configuration 2:
  • cpe:/o:apple:a_ux:2.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:bsd:bsd:4.3:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:*:*:*:*:*:*:*:* (Version <= 4.1.1)

  • Configuration CCN 1:
  • cpe:/o:windriver:bsdos:4.3:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:5.2:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:4.1.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:a_ux:2.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:4.0.5:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:5.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:5.1:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:5.1.1:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:5.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sgi irix *
    apple a ux 2.0.1
    bsd bsd 4.3
    sun sunos *
    windriver bsdos 4.3
    sgi irix 5.2
    sun sunos 4.1.1
    apple a ux 2.0.1
    sgi irix 4.0.5
    sgi irix 5.0.1
    sgi irix 5.1
    sgi irix 5.1.1
    sgi irix 5.0