VulnerabilityModified
CVE-2000-0615
LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.
LOW 2.1EPSS 0.48%
Does this matter?
Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.
Description
LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Affected
- astart technologies/lprng
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2000-07/0117.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/1447Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7361
- http://archives.neohapsis.com/archives/bugtraq/2000-07/0117.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/1447Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7361
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.