← Back

CVE-2000-0844

nvd nist
Published: Nov 14, 2000Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.

Affected (74)

Show all products
3 products
Openlinux Ebuilder
Openlinux
Openlinux Eserver
1 product
Linux
1 product
Immunix
1 product
Irix
1 product
Debian Linux
1 product
Aix
1 product
Mandrake Linux
1 product
Linux
1 product
Slackware Linux
2 products
Solaris
Sunos
1 product
Suse Linux
1 product
Secure Linux
1 product
Turbolinux
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.0
Conectiva
Version 4.0
Version 4.0es
Version 4.1
Version 4.2
Version 5.0
Version 5.1
Version 6.2
Sgi
Version 6.2
Version 6.3
Version 6.4
Version 6.5.1
Version 6.5.2m
Version 6.5.3
Version 6.5.3f
Version 6.5.3m
Version 6.5.4
Version 6.5.6
Version 6.5.7
Version 6.5.8
Version 6.5
Configuration B
53 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Version 2.3
Debian
Version 2.0
Version 2.1
Version 2.2
Version 2.3
Ibm
Version 3.2.4
Version 3.2.5
Version 3.2
Version 4.0
Version 4.1.1
Version 4.1.2
Version 4.1.3
Version 4.1.4
Version 4.1.5
Version 4.1
Version 4.2.1
Version 4.2
Version 4.3.1
Version 4.3.2
Version 4.3
Mandrakesoft
Version 7.0
Version 7.1
Redhat
Version 5.0
Version 5.1
Version 5.2
Version 6.0
Version 6.1
Version 6.2
Slackware
Version 7.0
Version 7.1
Version 2.6
Sun
Version 5.0
Version 5.1
Version 5.2
Version 5.3
Version 5.4
Version 5.5.1
Version 5.5
Version 5.7
Version 5.8
Suse
Version 6.1
Version 6.2
Version 6.3
Version 6.4
Version 7.0
Trustix
Version 1.0
Version 1.1
Turbolinux
Version 6.0.1
Version 6.0.2
Version 6.0.3
Version 6.0.4
Version 6.0

Related CWEs

References (24)

ftp://patches.sgi.com/support/free/security/advisories/20000901-01-P (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
ExploitPatchVendor Advisory
Source: cve@mitre.org
ExploitPatchVendor Advisory
ftp://patches.sgi.com/support/free/security/advisories/20000901-01-P (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.