CVE-2003-0144
lpr-ppd - buffer overflow
EPSS 1.9%
Description
Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.
How to fix CVE-2003-0144
To remediate CVE-2003-0144, upgrade the affected package to a fixed version below.
- Debian/lpr—upgrade to 1:2000.05.07-4.20 or later
- Debian/lpr—upgrade to 2000.05.07-4.3 or later
- Debian/lpr-ppd—upgrade to 0.72-2.1 or later
Is CVE-2003-0144 being exploited?
Low — EPSS is 1.9%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 1:2000.05.07-4.20
- from 0, < 2000.05.07-4.3
- from 0, < 0.72-2.1