CVE-2003-0144: Buffer Overflow
Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0144?
CVE-2003-0144 has been assessed as critical because it allows local users to gain root privileges through a buffer overflow.
How do I fix CVE-2003-0144?
To fix CVE-2003-0144, update the lpr or lprold package to a version that is not vulnerable.
Who is vulnerable to CVE-2003-0144?
Systems running affected versions of the lprm command in the lprold package, specifically SuSE 7.1 to 7.3 and OpenBSD 3.2 and earlier, are vulnerable.
What causes the vulnerability in CVE-2003-0144?
CVE-2003-0144 is caused by a buffer overflow due to insufficient validation of command line arguments for user input.
Can CVE-2003-0144 be exploited remotely?
CVE-2003-0144 cannot be exploited remotely; it requires local access to the system.