Back

CVE-2001-1583

lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when lpd invokes a mail program. NOTE: this might be the same vulnerability as CVE-2000-1220.

Published: Dec 31, 2001 Modified: Jun 16, 2026
CWE-78

CVSS Metrics

Affected Products (1)

Vendor Product Version
sun sunos *

GitHub Security Advisory GHSA-4xc7-h5vr-gqmj

lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 83.40%

Top 0% most likely to be exploited

Threat Score 75 / 100

Data Sources

NVD EPSS GitHub