Vulnerabilities > CVE-2004-0393 - Multiple vulnerability in Rlpr msg() Function

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
rlpr
critical
nessus
exploit available

Summary

Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string specifiers in a buffer that can not be resolved, which is provided to the syslog function.

Vulnerable Configurations

Part Description Count
Application
Rlpr
5

Exploit-Db

  • descriptionrlpr <= 2.04 msg() Remote Format String Exploit. CVE-2004-0393. Remote exploit for linux platform
    idEDB-ID:307
    last seen2016-01-31
    modified2004-06-25
    published2004-06-25
    reporterjaguar
    sourcehttps://www.exploit-db.com/download/307/
    titlerlpr <= 2.04 msg Remote Format String Exploit
  • descriptionRlpr 2.0 msg() Function Multiple Vulnerabilities. CVE-2004-0393. Remote exploit for linux platform
    idEDB-ID:24223
    last seen2016-02-02
    modified2004-06-19
    published2004-06-19
    reporter[email protected]
    sourcehttps://www.exploit-db.com/download/24223/
    titleRlpr 2.0 msg Function Multiple Vulnerabilities

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-524.NASL
descriptiondiscovered a format string vulnerability in rlpr, a utility for lpd printing without using /etc/printcap. While investigating this vulnerability, a buffer overflow was also discovered in related code. By exploiting one of these vulnerabilities, a local or remote user could potentially cause arbitrary code to be executed with the privileges of 1) the rlprd process (remote), or 2) root (local). CAN-2004-0393: format string vulnerability via syslog(3) in msg() function in rlpr CAN-2004-0454: buffer overflow in msg() function in rlpr
last seen2020-06-01
modified2020-06-02
plugin id15361
published2004-09-29
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/15361
titleDebian DSA-524-1 : rlpr - several vulnerabilities