CVE-1999-1102
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/1999
Last modified:
03/04/2025
Description
lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.
Impact
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:sgi:irix:*:*:*:*:*:*:*:* | 5.2 (including) | |
cpe:2.3:o:apple:a_ux:2.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:bsd:bsd:4.3:*:*:*:*:*:*:* | ||
cpe:2.3:o:sun:sunos:*:*:*:*:*:*:*:* | 4.1.1 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://ciac.llnl.gov/ciac/bulletins/e-25.shtml
- http://www.aenigma.net/resources/maillist/bugtraq/1994/0091.htm
- http://www.phreak.org/archives/security/8lgm/8lgm.lpr
- http://ciac.llnl.gov/ciac/bulletins/e-25.shtml
- http://www.aenigma.net/resources/maillist/bugtraq/1994/0091.htm
- http://www.phreak.org/archives/security/8lgm/8lgm.lpr