CVE-2000-1221 describes a critical authentication bypass vulnerability in the line printer daemon (lpd) within the lpr package, affecting multiple Linux operating systems including Debian, Red Hat, and SGI IRIX. The flaw stems from lpd's reliance on reverse-resolved hostnames for authentication, allowing remote attackers to bypass access controls by manipulating DNS records for their attacking IP address. This vulnerability carries a CVSS score of 10.0 (Critical), indicating a network-based attack with low complexity and complete compromise of confidentiality, integrity, and availability. While not on the KEV catalog or currently active on the Hot List, an exploit for Red Hat 6.1 / IRIX 6.5.18 leading to command execution is available on ExploitDB. Despite its age and high severity, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.5CPE matchmatch criteria | cpe:2.3:o:sgi:irix:6.5:*:*:*:*:*:*:* | ||
6.5.1CPE matchmatch criteria | cpe:2.3:o:sgi:irix:6.5.1:*:*:*:*:*:*:* | ||
6.5.2CPE matchmatch criteria | cpe:2.3:o:sgi:irix:6.5.2:*:*:*:*:*:*:* | ||
6.5.3CPE matchmatch criteria | cpe:2.3:o:sgi:irix:6.5.3:*:*:*:*:*:*:* | ||
6.5.4CPE matchmatch criteria | cpe:2.3:o:sgi:irix:6.5.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.