Junglewise Threat Intelligence

CVE-1999-0299: FreeBSD lpd buffer overflow via long DNS hostnames

CVE-1999-0299 · Severity: critical · CVSS 9.3 · Published 1997-03-05

Technologies: Freebsd. Vendors: Freebsd.

Executive brief

A vulnerability exists in the FreeBSD line printer daemon (lpd), a service responsible for managing print jobs. An attacker can exploit this flaw by providing a specially crafted, overly long hostname via DNS. Successful exploitation could allow an attacker to take complete control of the affected system, potentially leading to data theft or service disruption.

Technical details

The FreeBSD line printer daemon (lpd) is vulnerable to a classic buffer overflow. The flaw is triggered when the daemon processes a print request from a host with an excessively long DNS hostname, which exceeds the allocated buffer size in the stack. Because lpd often runs with elevated privileges to manage hardware and spooling, a remote, unauthenticated attacker can exploit this to overwrite the instruction pointer and execute arbitrary code with root privileges. This vulnerability is reachable over the network if the lpd service is exposed. Users should apply patches provided by the FreeBSD Project or upgrade to a version released after March 1997.

Affected products

  • FreeBSD Project FreeBSD Versions prior to March 1997

Timeline

  • 1997-03-05: disclosed: Initial publication date

References

Related threats