← Vulnerability feed

Vulnerability record · CVE-2001-1583 · published 31 December 2001

CVE-2001-1583: Solaris lpd control file command injection

Sun · Sunos

The in.lpd daemon in Solaris 8 and earlier fails to properly handle a crafted print job control file, allowing command injection when lpd invokes a mail program. A remote attacker can send a malicious job request to the print service and execute arbitrary commands on the host. The record notes this may be the same issue as CVE-2000-1220.

10.0 CVSS 2.0 High EPSS 83% · top 0.3% CWE-78 · OS command injection
10.0CVSS 2.0 base score
83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when lpd invokes a mail program. NOTE: this might be the same vulnerability as CVE-2000-1220.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityUnauthenticated remote command execution with complete impact and high EPSS, though the affected Solaris 8 and earlier platform is legacy.

What it is

The in.lpd daemon in Solaris 8 and earlier fails to properly handle a crafted print job control file, allowing command injection when lpd invokes a mail program. A remote attacker can send a malicious job request to the print service and execute arbitrary commands on the host. The record notes this may be the same issue as CVE-2000-1220.

Impact

An unauthenticated remote attacker gains arbitrary command execution, typically with the privileges of the lpd daemon, which can lead to full host compromise. The CVSS 2.0 vector rates complete confidentiality, integrity and availability impact.

Attack surface

Reachable over the network via the LPD print service (TCP 515); the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The flaw is triggered by a job request containing a crafted control file.

Exploitation

Not listed in CISA KEV, but EPSS is 0.834 (99.7th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code exists. A Metasploit module reference is present but the link is broken.

What to do

  • Apply the Solaris patch for the in.lpd control file handling flaw; consult Oracle/Sun advisories since the record does not list patch IDs.
  • Disable or stop the LPD print service on hosts that do not require network printing.
  • Restrict TCP 515 access to trusted print clients with host-based firewalls or network ACLs.
  • Run lpd with least privilege and monitor for unexpected child processes such as mail programs spawned by print jobs.

Detection

  • Monitor lpd logs and process trees for unexpected mail or shell processes spawned by in.lpd.
  • Alert on LPD job submissions containing shell metacharacters or unusual control file content.
  • Audit network flows to TCP 515 from untrusted sources and flag anomalous print job volume.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-1583 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-4435Sunos vulnerabilityUnspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability, related to C…EPSS 14%10.0CVE-2008-4619Sunos vulnerabilityThe RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted request to procedure 8 in progra…EPSS 12%10.0CVE-2008-2144Sunos vulnerabilityMultiple unspecified vulnerabilities in Solaris print service for Sun Solaris 8, 9, and 10 allow remote attackers to cause a denial of service or exe…EPSS 16%10.0CVE-2008-1369Sunos permissions and access controls vulnerabilityA certain incorrect Sun Solaris 10 image on SPARC Enterprise T5120 and T5220 servers has /etc/default/login and /etc/ssh/sshd_config files that confi…EPSS 2.6%10.0CVE-2007-3093Sun solaris vulnerabilityUnspecified vulnerability in the logging mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote atta…EPSS 4.7%10.0CVE-2007-0882Solaris telnet daemon argument injection bypasses authenticationThe telnet daemon (in.telnetd) in Solaris 10 and 11 mishandles certain client-supplied "-f" sequences, passing them to the login program as a request…EPSS 98%analysed10.0CVE-2004-1351Sun solaris vulnerabilityUnknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.EPSS 6.0%10.0CVE-2004-0523Mit kerberos vulnerabilityMultiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as …EPSS 12%

Source: NIST National Vulnerability Database (record CVE-2001-1583), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.