OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 4th quarter (Oct-Dec) 1996: Re: Linux & BSD's lpr exploit

Re: Linux & BSD's lpr exploit

Theo de Raadt (deraadtcvs.openbsd.org)
Fri, 25 Oct 1996 10:45:19 -0600

>  there is a bug in berkeley-derived lpr, which allows attacker to get
>root access (see freebsd-security for details). Here is exploit for Linux
>(tested on 2.0.20), for BSD (tested on FreeBSD 2.1) and a patch.

OpenBSD is not vulnerable.  This was found and fixed in mid-August.