lpadmin in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first argument to the command.
https://exchange.xforce.ibmcloud.com/vulnerabilities/6291
https://euvd.enisa.europa.eu/vulnerability/EUVD-2001-0571
http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html
http://archives.neohapsis.com/archives/bugtraq/2001-03/0421.html