First published: Wed Oct 18 2000(Updated: )
LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program to kill the process that was specified in the lpdprocess file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plus Technologies Lpplus | =3.3 | |
Plus Technologies Lpplus | =3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0880 has been classified with a moderate severity due to its implications for local privilege escalation.
To mitigate CVE-2000-0880, change the permissions of the lpdprocess file to remove world-writable access.
CVE-2000-0880 affects users of Plus Technologies Lpplus versions 3.2.2 and 3.3.
CVE-2000-0880 allows local users to kill arbitrary processes, potentially leading to denial of service or unauthorized actions.
There is no specific patch for CVE-2000-0880; users are advised to modify file permissions as a workaround.