First published: Wed Oct 18 2000(Updated: )
LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plus Technologies Lpplus | =3.3 | |
Plus Technologies Lpplus | =3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0879 is considered a high severity vulnerability due to the potential for arbitrary local users to exploit setuid root programs.
To fix CVE-2000-0879, remove the setuid bit from the affected LPPlus programs or restrict their execution permissions to prevent unauthorized access.
CVE-2000-0879 affects LPPlus versions 3.3 and 3.2.2.
CVE-2000-0879 is a local privilege escalation vulnerability.
CVE-2000-0879 cannot be exploited remotely as it requires local access to the system.