CVE Vulnerabilities

CVE-2000-0993

Published: Dec 19, 2000 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.

Affected Software

NameVendorStart VersionEnd Version
FreebsdFreebsd3.2 (including)3.2 (including)
FreebsdFreebsd3.3 (including)3.3 (including)
FreebsdFreebsd3.4 (including)3.4 (including)
FreebsdFreebsd3.5 (including)3.5 (including)
FreebsdFreebsd4.0 (including)4.0 (including)
NetbsdNetbsd1.4 (including)1.4 (including)
NetbsdNetbsd1.4.1 (including)1.4.1 (including)
NetbsdNetbsd1.4.2 (including)1.4.2 (including)
OpenbsdOpenbsd2.3 (including)2.3 (including)
OpenbsdOpenbsd2.4 (including)2.4 (including)
OpenbsdOpenbsd2.5 (including)2.5 (including)
OpenbsdOpenbsd2.6 (including)2.6 (including)
OpenbsdOpenbsd2.7 (including)2.7 (including)

References