CVE-2000-0844
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD
Description
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
Affected (74)
Products: Caldera: Openlinux Ebuilder, Openlinux, Openlinux Eserver · Conectiva: Linux · Immunix: Immunix · +10 more
Show all products
Caldera: Openlinux Ebuilder, Openlinux, Openlinux Eserver · Conectiva: Linux · Immunix: Immunix · Sgi: Irix · Debian: Debian Linux · Ibm: Aix · Mandrakesoft: Mandrake Linux · Redhat: Linux · Slackware: Slackware Linux · Sun: Solaris, Sunos · Suse: Suse Linux · Trustix: Secure Linux · Turbolinux: Turbolinux
Configuration A
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Version 2.3 | |
| Version 2.0 | |
| Version 3.2.4 | |
| Version 7.0 | |
| Version 5.0 | |
| Version 7.0 | |
| Version 2.6 | |
| Version 5.0 | |
| Version 6.1 | |
| Version 1.0 | |
| Version 6.0.1 |
Related CWEs
References (24)
ftp://patches.sgi.com/support/free/security/advisories/20000901-01-P (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
ExploitPatchVendor Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
ftp://patches.sgi.com/support/free/security/advisories/20000901-01-P (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.