Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2002-1285

EPSS 0.15% · P35
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2002-1285

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
LPRNG runlpr本地权限提升漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
LPRng是一款增强的、扩展的、移植的Berkeley LPR打印作业系统实现,可使用在多种操作系统下。 LPRng中包含的runlpr工具对用户提交的参数缺少正确检查,本地攻击者可以利用这个漏洞以欺骗lpr以'root'用户权限在系统上执行任意命令。 lprng包含的"runlpr"工具存在漏洞允许lp用户以root用户权限执行lpr程序。本地攻击者可以传递包含恶意字符串的命令行参数给以root权限运行的lpr,欺骗lpr以root用户权限执行命令行参数包含的命令。 目前我们还不清楚漏洞详细细节。 <*
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2002-1285

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2002-1285

Please Login to view more intelligence information

Same Patch Batch · n/a · 2002-11-14 · 17 CVEs total

CVE-2002-1247KDE KIO子系统网络协议实现任意命令执行漏洞
CVE-2002-1276SquirrelMail global.php 跨站脚本漏洞
CVE-2002-1279MasqMail缓冲区溢出漏洞
CVE-2002-1281KDE KIO子系统网络协议实现任意命令执行漏洞
CVE-2002-1282KDE KIO子系统网络协议实现任意命令执行漏洞
CVE-2002-1283Novell Netware eMFrame iManage缓冲区溢出漏洞
CVE-2002-1286Microsoft JVM URI解析漏洞
CVE-2002-1287Microsoft JVM类装载缓冲区溢出漏洞
CVE-2002-1288Microsoft JVM远程信息泄露漏洞
CVE-2002-1289Microsoft JVM INativeServices未授权内存访问漏洞
CVE-2002-1290Microsoft JVM未授权剪贴板访问漏洞
CVE-2002-1291Microsoft JVM Codebase信息泄露漏洞
CVE-2002-1292Microsoft JVM Package访问限制可绕过漏洞
CVE-2002-1293Microsoft JVM CAB文件装载漏洞
CVE-2002-1294Microsoft JVM HTML对象应用拒绝服务攻击漏洞
CVE-2002-1295Microsoft JVM HTML Applet标记类限制可绕过漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2002-1285

No comments yet


Leave a comment