Vulnerability Name:

CVE-2003-0144 (CCN-11473)

Assigned:2003-03-05
Published:2003-03-05
Updated:2017-07-11
Summary:Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: CONFIRM
Type: UNKNOWN
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch

Source: CCN
Type: SGI Security Advisory 20030406-01-P
Multiple Vulnerabilities in BSD LPR Subsystem

Source: CCN
Type: SGI Security Advisory 20030406-02-P
Multiple Vulnerabilities in BSD LPR Subsystem

Source: SGI
Type: UNKNOWN
20030406-02-P

Source: CCN
Type: BugTraq Mailing List, Wed Mar 05 2003 - 16:33:25 CST
potential buffer overflow in lprm (fwd)

Source: MITRE
Type: CNA
CVE-2003-0144

Source: BUGTRAQ
Type: UNKNOWN
20030305 potential buffer overflow in lprm (fwd)

Source: BUGTRAQ
Type: UNKNOWN
20030308 OpenBSD lprm(1) exploit

Source: CCN
Type: SA8293
SuSE lprm command buffer overflow

Source: SECUNIA
Type: UNKNOWN
8293

Source: CCN
Type: CIAC Information Bulletin N-076
Multiple Vulnerabilities in BSD LPR Subsystem

Source: DEBIAN
Type: UNKNOWN
DSA-267

Source: DEBIAN
Type: UNKNOWN
DSA-275

Source: DEBIAN
Type: DSA 267-1
lpr -- buffer overflow

Source: DEBIAN
Type: DSA-267
lpr -- buffer overflow

Source: DEBIAN
Type: DSA-275
lpr-ppd -- buffer overflow

Source: MANDRAKE
Type: UNKNOWN
MDKSA-2003:059

Source: SUSE
Type: UNKNOWN
SuSE-SA:2003:0014

Source: CCN
Type: OpenBSD Web site
010: SECURITY FIX: March 5, 2003

Source: CCN
Type: OSVDB ID: 7549
lprold lpr Package lprm Command Line Overflow

Source: BID
Type: Exploit, Patch, Vendor Advisory
7025

Source: CCN
Type: BID-7025
Multiple Vendor LPRM Local Buffer Overflow Vulnerability

Source: CCN
Type: TLSA-2003-21
Buffer overflows

Source: XF
Type: UNKNOWN
lprm-bo(11473)

Source: XF
Type: UNKNOWN
lprm-bo(11473)

Source: SUSE
Type: SUSE-SA:2003:0014
lprold: local privilege escalation

Vulnerable Configuration:Configuration 1:
  • cpe:/a:lprold:lprold:3.0.48:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:bsd:lpr:0.48:*:*:*:*:*:*:*
  • OR cpe:/o:bsd:lpr:2000-05-07:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:2.2:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:2.2.2:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:2.2.3:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:2.2.4:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:2.2.5:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:2.2.6:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:2.0:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:2.1:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:2.2:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:2.3:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:2.4:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:2.5:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:2.6:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:2.7:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:2.8:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:2.9:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:3.1:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:3.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.debian:def:275
    V
    buffer overflow
    2003-04-02
    oval:org.debian:def:267
    V
    buffer overflow
    2003-03-24
    BACK
    lprold lprold 3.0.48
    bsd lpr 0.48
    bsd lpr 2000-05-07
    freebsd freebsd 2.2
    freebsd freebsd 2.2.2
    freebsd freebsd 2.2.3
    freebsd freebsd 2.2.4
    freebsd freebsd 2.2.5
    freebsd freebsd 2.2.6
    openbsd openbsd 2.0
    openbsd openbsd 2.1
    openbsd openbsd 2.2
    openbsd openbsd 2.3
    openbsd openbsd 2.4
    openbsd openbsd 2.5
    openbsd openbsd 2.6
    openbsd openbsd 2.7
    openbsd openbsd 2.8
    openbsd openbsd 2.9
    openbsd openbsd 3.0
    openbsd openbsd 3.1
    openbsd openbsd 3.2