VYPR
Unrated severityNVD Advisory· Published Dec 6, 2004· Updated Apr 16, 2026

CVE-2004-0454

CVE-2004-0454

Description

Buffer overflow in rlprd 2.04 msg function allows local users to execute arbitrary code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Buffer overflow in rlprd 2.04 msg function allows local users to execute arbitrary code.

Vulnerability

A buffer overflow vulnerability exists in the msg function of the rlpr daemon (rlprd) version 2.04. This flaw can be triggered when processing specially crafted input, leading to memory corruption. The affected package is rlpr version 2.04 on Debian systems.

Exploitation

An attacker with local access to the system can exploit this vulnerability by sending a maliciously crafted message to the rlprd daemon. No additional authentication is required beyond local user privileges. The overflow occurs during message handling, allowing the attacker to overwrite adjacent memory.

Impact

Successful exploitation allows arbitrary code execution with the privileges of the rlprd daemon, typically running as root or the lp user. This can lead to full compromise of the affected system, including unauthorized access, data modification, or denial of service.

Mitigation

Debian released security advisory DSA-524 [1] addressing this issue. The fixed version is rlpr 2.04-1.1 or later. Users should upgrade their packages immediately. No workarounds are documented; upgrading is the recommended mitigation.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

6
  • Rlpr/Rlpr6 versions
    cpe:2.3:a:rlpr:rlpr:2.0:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:rlpr:rlpr:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:rlpr:rlpr:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:rlpr:rlpr:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:rlpr:rlpr:2.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:rlpr:rlpr:2.0.4:*:*:*:*:*:*:*
    • (no CPE)range: = 2.04

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.