Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2000-11-13 21:00
Updated : 2018-10-30 09:26
NVD link : CVE-2000-0844
Mitre link : CVE-2000-0844
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
caldera
- openlinux_eserver
- openlinux_ebuilder
- openlinux
turbolinux
- turbolinux
sun
- solaris
- sunos
mandrakesoft
- mandrake_linux
ibm
- aix
trustix
- secure_linux
immunix
- immunix
slackware
- slackware_linux
redhat
- linux
sgi
- irix
suse
- suse_linux
debian
- debian_linux
conectiva
- linux