Lucene search

K
suseSuseSUSE-SA:2002:040
HistoryOct 31, 2002 - 11:02 a.m.

local privilege escalation, in lprng, html2ps

2002-10-3111:02:36
lists.opensuse.org
12

0.04 Low

EPSS

Percentile

92.1%

The lprng package contains the “runlpr” program which allows the lp user to execute the lpr program as root. Local attackers can pass certain commandline arguments to lpr running as root, fooling it to execute arbitrary commands as root. This has been fixed. Note that this vulnerability can only be exploited if the attacker has previously gained access to the lp account.

0.04 Low

EPSS

Percentile

92.1%