HIGH · 10.0

CVE-2000-0844

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gette...

Vulnerability Description

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CalderaOpenlinux Ebuilder3.0
ImmunixImmunix6.2
ConectivaLinux4.0
SgiIrix6.2
CalderaOpenlinuxAll versions
CalderaOpenlinux Eserver2.3
DebianDebian Linux2.0
IbmAix3.2
MandrakesoftMandrake Linux7.0
RedhatLinux5.0
SlackwareSlackware Linux7.0
SunSolaris2.6
SunSunos5.0
SuseSuse Linux6.1
TrustixSecure Linux1.0
TurbolinuxTurbolinux6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2000-0844?

CVE-2000-0844 is a vulnerability with a CVSS score of 10.0 (HIGH). Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gette...

How severe is CVE-2000-0844?

CVE-2000-0844 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2000-0844?

Check the references section above for vendor advisories and patch information. Affected products include: Caldera Openlinux Ebuilder, Immunix Immunix, Conectiva Linux, Sgi Irix, Caldera Openlinux.