LPRng 3.6.x improperly installs lpd as setuid root, which...
        
  Low severity
        
          Unreviewed
      
        Published
          Apr 30, 2022 
          to the GitHub Advisory Database
          •
          Updated Jan 30, 2023 
      
  
Description
        Published by the National Vulnerability Database
      Jul 19, 2000 
    
  
        Published to the GitHub Advisory Database
      Apr 30, 2022 
    
  
        Last updated
      Jan 30, 2023 
    
  
LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.
References