Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a "transfer job" routine.
https://exchange.xforce.ibmcloud.com/vulnerabilities/6718
http://xforce.iss.net/alerts/advise80.php
http://www.securityfocus.com/bid/2894
http://www.cert.org/advisories/CA-2001-15.html
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/206