← Vulnerability feed

Vulnerability record · CVE-2000-0917 · published 19 December 2000

CVE-2000-0917: LPRng use_syslog format string allows remote command execution

Caldera · Openlinux Ebuilder

LPRng 3.6.24 contains a format string vulnerability in the use_syslog() function. Because the flaw is remotely reachable and leads to arbitrary command execution, it is a full-compromise issue for exposed print services. The record does not list affected versions beyond 3.6.24.

10.0 CVSS 2.0 High EPSS 79% · top 0.4%
10.0CVSS 2.0 base score
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
14References, 2 tagged exploit
23 Sep 2026Last modified by NVD

Description

Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityThe flaw is remotely exploitable without authentication and yields arbitrary command execution, and public exploit material plus a very high EPSS score make near-term exploitation plausible.

What it is

LPRng 3.6.24 contains a format string vulnerability in the use_syslog() function. Because the flaw is remotely reachable and leads to arbitrary command execution, it is a full-compromise issue for exposed print services. The record does not list affected versions beyond 3.6.24.

Impact

A remote attacker can execute arbitrary commands on the host running LPRng, typically with the privileges of the print service. That yields full control of confidentiality, integrity and availability on the affected system.

Attack surface

The CVSS 2.0 vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication and no user interaction. It is triggered through LPRng's syslog logging path, so any remote input that reaches use_syslog() is a candidate vector.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.78658, 99.566th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware group is documented as using it.

What to do

  • Upgrade LPRng to a version later than 3.6.24, or apply the vendor patches referenced in the Red Hat, Caldera, Trustix and FreeBSD advisories.
  • If LPRng cannot be patched immediately, restrict network access to the print service (TCP 515 and related ports) to trusted hosts only.
  • Disable or remove LPRng on systems that do not need to provide print services.
  • Run the print daemon with the least privilege possible and isolate it from sensitive data and credentials.
  • Monitor vendor advisories for this product line, since the record does not enumerate all affected versions.

Detection

  • Inspect LPRng and system logs for format-string-like input (percent specifiers such as %n, %s, %x) reaching the print service.
  • Alert on unexpected child processes or command execution spawned by the LPRng daemon.
  • Monitor network traffic to the print service from untrusted or unusual source addresses.
  • Audit hosts for LPRng 3.6.24 or earlier installations and verify patch level.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2000-0917 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2004-0902Mozilla vulnerabilityMultiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote att…EPSS 10%10.0CVE-2004-0903Mozilla vulnerabilityStack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Th…EPSS 9.7%10.0CVE-2004-1025Enlightenment imlib vulnerabilityMultiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cau…EPSS 5.2%10.0CVE-2004-1026Enlightenment imlib vulnerabilityMultiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote atta…EPSS 4.9%10.0CVE-2004-0904Mozilla firefox vulnerabilityInteger overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow r…EPSS 8.0%10.0CVE-2003-0248Redhat linux vulnerabilityThe mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.EPSS 3.7%10.0CVE-2003-0041Mit kerberos ftp client os command injection vulnerabilityKerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.EPSS 3.5%

Source: NIST National Vulnerability Database (record CVE-2000-0917), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.