rhsa.2000-002-01.lpr...

- AV AC AU C I A
发布: 2000-01-10
修订: 2025-04-13

Two security vulnerabilities exist in the lpd (line printer daemon) shipped with the lpr package. First, authentication was not thorough enough. If a remote user was able to control their own DNS so that their IP address resolved to the hostname of the print server, access would be granted, when it should not be. Secondly, it was possible in the control file of a print job to specify arguments to sendmail. Through careful manipulation of control and data files, this could cause sendmail to be executed with a user-specified configuration file. This could lead very easily to a root compromise.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息