vendor:
lpstat
by:
LAST STAGE OF DELIRIUM
7.5
CVSS
HIGH
File Inclusion
CWE
Product Name: lpstat
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:irix:lpstat
Platforms Tested: IRIX
2000
Vulnerability in /usr/bin/lpstat
This exploit allows an attacker to include arbitrary files by manipulating the NETTYPE variable in the lpstat command. By creating a malicious file and library, the attacker can execute arbitrary code as root.
Mitigation:
Update the vulnerable lpstat command with a patched version or implement access controls to prevent unauthorized access to the lpstat command.