Vulnerability record · CVE-2001-1583 · published 31 December 2001
CVE-2001-1583: Solaris lpd control file command injection
Sun · Sunos
The in.lpd daemon in Solaris 8 and earlier fails to properly handle a crafted print job control file, allowing command injection when lpd invokes a mail program. A remote attacker can send a malicious job request to the print service and execute arbitrary commands on the host. The record notes this may be the same issue as CVE-2000-1220.
Description
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when lpd invokes a mail program. NOTE: this might be the same vulnerability as CVE-2000-1220.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote command execution with complete impact and high EPSS, though the affected Solaris 8 and earlier platform is legacy.
What it is
The in.lpd daemon in Solaris 8 and earlier fails to properly handle a crafted print job control file, allowing command injection when lpd invokes a mail program. A remote attacker can send a malicious job request to the print service and execute arbitrary commands on the host. The record notes this may be the same issue as CVE-2000-1220.
Impact
An unauthenticated remote attacker gains arbitrary command execution, typically with the privileges of the lpd daemon, which can lead to full host compromise. The CVSS 2.0 vector rates complete confidentiality, integrity and availability impact.
Attack surface
Reachable over the network via the LPD print service (TCP 515); the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The flaw is triggered by a job request containing a crafted control file.
Exploitation
Not listed in CISA KEV, but EPSS is 0.834 (99.7th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code exists. A Metasploit module reference is present but the link is broken.
What to do
- Apply the Solaris patch for the in.lpd control file handling flaw; consult Oracle/Sun advisories since the record does not list patch IDs.
- Disable or stop the LPD print service on hosts that do not require network printing.
- Restrict TCP 515 access to trusted print clients with host-based firewalls or network ACLs.
- Run lpd with least privilege and monitor for unexpected child processes such as mail programs spawned by print jobs.
Detection
- Monitor lpd logs and process trees for unexpected mail or shell processes spawned by in.lpd.
- Alert on LPD job submissions containing shell metacharacters or unusual control file content.
- Audit network flows to TCP 515 from untrusted sources and flag anomalous print job volume.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://marc.info/?l=bugtraq&m=99929694701826&w=2 | Mailing ListThird Party Advisory |
| http://metasploit.com/projects/Framework/modules/exploits/solaris_lpd_exec.pm | Broken Link |
| http://www.derkeiler.com/Mailing-Lists/securityfocus/incidents/2001-08/0490.html | Broken Link |
| http://www.osvdb.org/15131 | Broken Link |
| http://www.securityfocus.com/bid/3274 | ExploitThird Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/7087 | Third Party AdvisoryVDB Entry |
| http://marc.info/?l=bugtraq&m=99929694701826&w=2 | Mailing ListThird Party Advisory |
| http://metasploit.com/projects/Framework/modules/exploits/solaris_lpd_exec.pm | Broken Link |
| http://www.derkeiler.com/Mailing-Lists/securityfocus/incidents/2001-08/0490.html | Broken Link |
| http://www.osvdb.org/15131 | Broken Link |
| http://www.securityfocus.com/bid/3274 | ExploitThird Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/7087 | Third Party AdvisoryVDB Entry |
Track CVE-2001-1583 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2001-1583), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.