LPRng是Berkeley lpr打印工具的一种实现。 某些Linux系统附带的LPRng程序存在一个格式化串溢出漏洞,远程攻击者可以利用此漏洞通过溢出攻击在主机上以root用户权限执行任意指令。 LPRng编程实现中有一个函数use_syslog(),此函数把用户的输入未加检查就作为一个格式化串传给syslog()函数。远程攻击者可以通过输入一个恶意的格式化串来破坏程序执行流程。在测试中,这个漏洞可被攻击者利用来从远程在主机上以root用户的权限执行任意指令。 有问题的代码部分在: /LPRng-3.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2000-1024 | eWave ServletExec权限许可漏洞 | |
| CVE-2000-1001 | Element InstantShop add_2_basket.asp漏洞 | |
| CVE-2000-1002 | Stalker CommuniGate Pro漏洞 | |
| CVE-2000-1003 | Windows 95和Windows 98 NETBIOS客户端拒绝服务漏洞 | |
| CVE-2000-1004 | OpenBSD photurisd格式字符串漏洞 | |
| CVE-2000-1005 | Extropia WebStore远程目录遍历文件泄露漏洞 | |
| CVE-2000-1006 | Microsoft Exchange Server 安全漏洞 | |
| CVE-2000-1007 | I-gear漏洞 | |
| CVE-2000-1010 | OpenBSD talkd格式化字符串漏洞 | |
| CVE-2000-1011 | FreeBSD catopen()函数缓冲区溢出漏洞 | |
| CVE-2000-1014 | Unixware SCO help http server search97.cgi CGI命令执行漏洞 | |
| CVE-2000-1016 | SuSE漏洞 | |
| CVE-2000-1018 | shred漏洞 | |
| CVE-2000-1019 | Ultraseek搜索引擎漏洞 | |
| CVE-2000-1022 | Cisco Secure PIX Firewall漏洞 | |
| CVE-2000-1043 | Mandrake Linux格式化字符串漏洞 | |
| CVE-2000-1040 | ypbind对数函数格式化字符串漏洞 | |
| CVE-2000-1041 | ypbind缓冲区溢出漏洞 | |
| CVE-2000-1042 | Mandrake Linux ypserv缓冲区溢出漏洞 | |
| CVE-2000-1038 | IBM AS/400 Firewall web管理界面漏洞 |
Showing top 20 of 232 CVEs. View all on vendor page → →
No comments yet