Vulnerability record · CVE-2000-0917 · published 19 December 2000
CVE-2000-0917: LPRng use_syslog format string allows remote command execution
Caldera · Openlinux Ebuilder
LPRng 3.6.24 contains a format string vulnerability in the use_syslog() function. Because the flaw is remotely reachable and leads to arbitrary command execution, it is a full-compromise issue for exposed print services. The record does not list affected versions beyond 3.6.24.
Description
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityThe flaw is remotely exploitable without authentication and yields arbitrary command execution, and public exploit material plus a very high EPSS score make near-term exploitation plausible.
What it is
LPRng 3.6.24 contains a format string vulnerability in the use_syslog() function. Because the flaw is remotely reachable and leads to arbitrary command execution, it is a full-compromise issue for exposed print services. The record does not list affected versions beyond 3.6.24.
Impact
A remote attacker can execute arbitrary commands on the host running LPRng, typically with the privileges of the print service. That yields full control of confidentiality, integrity and availability on the affected system.
Attack surface
The CVSS 2.0 vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication and no user interaction. It is triggered through LPRng's syslog logging path, so any remote input that reaches use_syslog() is a candidate vector.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.78658, 99.566th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware group is documented as using it.
What to do
- Upgrade LPRng to a version later than 3.6.24, or apply the vendor patches referenced in the Red Hat, Caldera, Trustix and FreeBSD advisories.
- If LPRng cannot be patched immediately, restrict network access to the print service (TCP 515 and related ports) to trusted hosts only.
- Disable or remove LPRng on systems that do not need to provide print services.
- Run the print daemon with the least privilege possible and isolate it from sensitive data and credentials.
- Monitor vendor advisories for this product line, since the record does not enumerate all affected versions.
Detection
- Inspect LPRng and system logs for format-string-like input (percent specifiers such as %n, %s, %x) reaching the print service.
- Alert on unexpected child processes or command execution spawned by the LPRng daemon.
- Monitor network traffic to the print service from untrusted or unusual source addresses.
- Audit hosts for LPRng 3.6.24 or earlier installations and verify patch level.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2000-0917 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2000-0917), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.