Vulnerability CVE-2000-0844


Published: 2000-11-14   Modified: 2012-02-12

Description:
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Turbolinux -> Turbolinux 
Trustix -> Secure linux 
SUSE -> Suse linux 
SUN -> Sunos 
SUN -> Solaris 
Slackware -> Slackware linux 
SGI -> IRIX 
Redhat -> Linux 
Mandrakesoft -> Mandrake linux 
Immunix -> Immunix 
IBM -> AIX 
Debian -> Debian linux 
Conectiva -> Linux 
Caldera -> Openlinux ebuilder 
Caldera -> Openlinux 
Caldera -> Openlinux eserver 

 References:
ftp://patches.sgi.com/support/free/security/advisories/20000901-01-P
http://archives.neohapsis.com/archives/bugtraq/2000-08/0436.html
http://archives.neohapsis.com/archives/bugtraq/2000-08/0457.html
http://archives.neohapsis.com/archives/bugtraq/2000-10/0427.html
http://archives.neohapsis.com/archives/tru64/2000-q4/0000.html
http://www.calderasystems.com/support/security/advisories/CSSA-2000-030.0.txt
http://www.debian.org/security/2000/20000902
http://www.novell.com/linux/security/advisories/adv5_draht_glibc_txt.html
http://www.redhat.com/support/errata/RHSA-2000-057.html
http://www.securityfocus.com/bid/1634
https://exchange.xforce.ibmcloud.com/vulnerabilities/5176

Copyright 2024, cxsecurity.com

 

Back to Top