Solaris 7 lp Buffer Overflow

HIGH (7.2) No Patch (9369 days)

Threat Intelligence

⚠️ CRITICAL GAP - Exploits exist but no detection available
EPSS Score: 0.13% chance of exploitation (percentile: 33%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: Exploit-DB

How we test →

What is it?

The Solaris 7 lp is a utility used to manage print queues. A buffer overflow vulnerability in this utility allows local users to gain root privileges by sending a specially crafted -d option.

Am I affected?

This is Solaris 7, specifically the lp utility. Version info not stated in advisory. Check with your system administrator if you're running an older version of Solaris or have a similar utility installed.

Affected Products

Sun Microsystems / Solaris 7 lp

How to fix

Immediate mitigations:
- Restrict access to the lp utility (e.g., chown lp:lp lp /dev/lp0)
- Monitor for suspicious print queue activity

To fix, download and install a patched version from archives.neohapsis.com. No public patch link is available in the advisory.