CVE-2007-5381
Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to be printed, as demonstrated by a telnet session to the LPD from a source port other than 515.
- Affected products
- Cisco Ios
- Cisco Ios
- = 10.3, 10.3\(3.3\), 10.3\(3.4\), 10.3\(4.2\), 10.3\(4.3\), 10.3\(16\), 10.3\(19a\), 11, 11.0, 11.0\(12\), 11.0\(17\), 11.0\(17\)bt, 11.0\(18\), 11.0\(20.3\), 11.0\(22a\), 11.0\(22b\), 11.0\(x\), 11.0.12\(a\)bt, 11.1, 11.1\(5\), 11.1\(7\), 11.1\(7\)aa, 11.1\(7\)ca, 11.1\(9\)ia, 11.1\(11\), 11.1\(12\), 11.1\(13\), 11.1\(13\)aa, 11.1\(13\)ca, 11.1\(13\)ia, 11.1\(14\), 11.1\(15\), 11.1\(15\)aa, 11.1\(15\)ca, 11.1\(15\)ia, 11.1\(16\), 11.1\(16\)aa, 11.1\(16\)ia, 11.1\(17\), 11.1\(17\)cc
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 14.7% (96th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2007-10-12
CVE-2007-5381 at NVD
1 known exploit for CVE-2007-5381
Proof-of-concept code and exploit modules indexed by Sploitus