Executive brief
A vulnerability exists in the BSD line printer daemon, a service used to manage print jobs across a network. An attacker could exploit this flaw to remotely delete files, create unauthorized files, or execute arbitrary commands on the affected system. This could lead to a complete system compromise, data loss, or unauthorized access to sensitive information.
Technical details
The BSD line printer daemon (lpd) is susceptible to multiple flaws involving improper handling of print job requests. An unauthenticated remote attacker can exploit these weaknesses to create or delete arbitrary files on the host system or execute commands with the privileges of the lpd process. The vulnerability typically stems from insufficient validation of control files or command-line arguments passed to the daemon. While the attack vector is network-based, successful exploitation may require specific environmental conditions or configurations, as reflected in the high access complexity. Patches were historically released by various BSD-derived operating system vendors to address these issues in the late 1990s.
Affected products
- BSD Line Printer Daemon (lpd)
Timeline
- 1997-10-02: disclosed