← Vulnerability feed

Vulnerability record · CVE-1999-1102 · published 31 December 1999

CVE-1999-1102: Sgi irix vulnerability

Sgi · Irix

lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.

2.1 CVSS 2.0 Low EPSS 0.43% · top 64.9%
2.1CVSS 2.0 base score
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.

AV:L/AC:L/Au:N/C:N/I:P/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-1999-1102 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-4435Sunos vulnerabilityUnspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability, related to C…EPSS 14%10.0CVE-2010-1039Hp nfs\/oncplus vulnerabilityFormat string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.…EPSS 20%10.0CVE-2008-4619Sunos vulnerabilityThe RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted request to procedure 8 in progra…EPSS 12%10.0CVE-2008-2144Sunos vulnerabilityMultiple unspecified vulnerabilities in Solaris print service for Sun Solaris 8, 9, and 10 allow remote attackers to cause a denial of service or exe…EPSS 16%10.0CVE-2008-1369Sunos permissions and access controls vulnerabilityA certain incorrect Sun Solaris 10 image on SPARC Enterprise T5120 and T5220 servers has /etc/default/login and /etc/ssh/sshd_config files that confi…EPSS 2.6%10.0CVE-2007-3093Sun solaris vulnerabilityUnspecified vulnerability in the logging mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote atta…EPSS 4.7%10.0CVE-2007-0882Solaris telnet daemon argument injection bypasses authenticationThe telnet daemon (in.telnetd) in Solaris 10 and 11 mishandles certain client-supplied "-f" sequences, passing them to the login program as a request…EPSS 98%analysed10.0CVE-2004-0139Sgi irix vulnerabilityUnknown vulnerability in the bsd.a kernel networking for SGI IRIX 6.5.22 through 6.5.25, and possibly earlier versions, in which "t_unbind changes t_…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-1999-1102), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.