Description
lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.
Affected products
- Apple / a_ux2.0.1 – 2.0.1
- BSD / bsd4.3 – 4.3
- sgi / irix5.2
- sun / sunos4.1.1