---
id: CVE-1999-0032
title: >-
  Buffer overflow in lpr, as used in BSD-based systems including Linux, allows
  local users to execute arbitrary code as root via a long -C (classification)
  command line option.
summary: >-
  Buffer overflow in lpr, as used in BSD-based systems including Linux, allows
  local users to execute arbitrary code as root via a long -C (classification)
  command line option.
severity: high
cvss: 7.2
cvssVector: 'AV:L/AC:L/Au:N/C:C/I:C/A:C'
published: '1996-10-25'
updated: '2026-06-16'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-1999-0032'
references:
  - url: 'ftp://patches.sgi.com/support/free/security/advisories/19980402-01-PX'
    label: cve@mitre.org
  - url: 'http://www.ciac.org/ciac/bulletins/i-042.shtml'
    label: cve@mitre.org
  - url: 'http://www.securityfocus.com/bid/707'
    label: cve@mitre.org
  - url: 'ftp://patches.sgi.com/support/free/security/advisories/19980402-01-PX'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.ciac.org/ciac/bulletins/i-042.shtml'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/707'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.00991
epssPercentile: 0.61087
ingestedAt: '2026-06-22T15:59:08.117Z'
exploitAvailable: true
exploits:
  exploitdb: true
  checkedAt: '2026-09-24T07:52:46.232Z'
---

## Overview

Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
