Lucene search

K
cve[email protected]CVE-2000-1221
HistoryApr 21, 2005 - 4:00 a.m.

CVE-2000-1221

2005-04-2104:00:00
web.nvd.nist.gov
29
cve-2000-1221
lpd
lpr package
linux
dns attacks
reverse-resolved hostname
access controls

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.7 Medium

AI Score

Confidence

Low

0.021 Low

EPSS

Percentile

89.2%

The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.

Affected configurations

NVD
Node
sgiirixMatch6.5
OR
sgiirixMatch6.5.1
OR
sgiirixMatch6.5.2
OR
sgiirixMatch6.5.3
OR
sgiirixMatch6.5.4
OR
sgiirixMatch6.5.5
OR
sgiirixMatch6.5.6
OR
sgiirixMatch6.5.7
OR
sgiirixMatch6.5.8
OR
sgiirixMatch6.5.9
OR
sgiirixMatch6.5.10
OR
sgiirixMatch6.5.11
OR
sgiirixMatch6.5.12
OR
sgiirixMatch6.5.13
OR
sgiirixMatch6.5.14f
OR
sgiirixMatch6.5.14m
OR
sgiirixMatch6.5.15f
OR
sgiirixMatch6.5.15m
OR
sgiirixMatch6.5.16f
OR
sgiirixMatch6.5.16m
OR
sgiirixMatch6.5.17f
OR
sgiirixMatch6.5.17m
OR
sgiirixMatch6.5.18f
OR
sgiirixMatch6.5.18m
Node
debiandebian_linuxMatch2.1
OR
redhatlinuxMatch4.1
OR
redhatlinuxMatch4.2
OR
redhatlinuxMatch5.0
OR
redhatlinuxMatch5.2i386
OR
redhatlinuxMatch6.0
OR
redhatlinuxMatch6.1i386

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.7 Medium

AI Score

Confidence

Low

0.021 Low

EPSS

Percentile

89.2%

Related for CVE-2000-1221