Description
LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.
Product(s):
- Astart Technologies LPRng 3.6.10
- Astart Technologies LPRng 3.6.11
- Astart Technologies LPRng 3.6.12
- Astart Technologies LPRng 3.6.13
- Astart Technologies LPRng 3.6.14
- Astart Technologies LPRng 3.6.15
- Astart Technologies LPRng 3.6.1
- Astart Technologies LPRng 3.6.2
- Astart Technologies LPRng 3.6.3
- Astart Technologies LPRng 3.6.4
- Astart Technologies LPRng 3.6.5
- Astart Technologies LPRng 3.6.6
- Astart Technologies LPRng 3.6.7
- Astart Technologies LPRng 3.6.8
- Astart Technologies LPRng 3.6.9
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-2000-0615, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2000-0615 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.