CVE-2003-0144 EXPLOIT
7.2
HIGH · CVSS 2.0 · EPSS 1.9% (pctl 79)
Patch early
A public exploit exists.
Description
Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.
Scoring
| CVSS | 7.2 (HIGH, v2.0) |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 1.91% — more likely to be exploited than 79% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-03-31 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| bsd | lpr |
| freebsd | freebsd |
| lprold | lprold |
| openbsd | openbsd |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | BSD 'lpr' 2000.05.07/0.48/0.72 / lpr-ppd 0.72 - Local Buffer Overflow (1) | 1998-04-22 |
| exploit-db | BSD 'lpr' 2000.05.07/0.48/0.72 / lpr-ppd 0.72 - Local Buffer Overflow (2) | 1998-04-22 |
References
- ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch
- ftp://patches.sgi.com/support/free/security/advisories/20030406-02-P
- http://marc.info/?l=bugtraq&m=104690434504429&w=2
- http://marc.info/?l=bugtraq&m=104714441925019&w=2
- http://secunia.com/advisories/8293
- http://www.debian.org/security/2003/dsa-267
- http://www.debian.org/security/2003/dsa-275
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:059
- http://www.novell.com/linux/security/advisories/2003_014_lprold.html
- http://www.securityfocus.com/bid/7025
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11473
- ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch
- ftp://patches.sgi.com/support/free/security/advisories/20030406-02-P
- http://marc.info/?l=bugtraq&m=104690434504429&w=2
- http://marc.info/?l=bugtraq&m=104714441925019&w=2
- http://secunia.com/advisories/8293
- http://www.debian.org/security/2003/dsa-267
- http://www.debian.org/security/2003/dsa-275
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:059
- http://www.novell.com/linux/security/advisories/2003_014_lprold.html
→ the Explorer · watch your stack · NVD