Vulnerability Description
LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.
CVSS Score
2.1
LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Astart Technologies | Lprng | 3.6.1 |
References
- http://archives.neohapsis.com/archives/bugtraq/2000-07/0117.htmlPatchVendor Advisory
- http://www.securityfocus.com/bid/1447ExploitPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7361
- http://archives.neohapsis.com/archives/bugtraq/2000-07/0117.htmlPatchVendor Advisory
- http://www.securityfocus.com/bid/1447ExploitPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7361
FAQ
What is CVE-2000-0615?
CVE-2000-0615 is a vulnerability with a CVSS score of 2.1 (LOW). LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.
How severe is CVE-2000-0615?
CVE-2000-0615 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2000-0615?
Check the references section above for vendor advisories and patch information. Affected products include: Astart Technologies Lprng.