CVE Vulnerabilities

CVE-2000-0993

Published: Dec 19, 2000 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.

Affected Software 

Name Vendor Start Version End Version
Freebsd Freebsd 3.2 (including) 3.2 (including)
Freebsd Freebsd 3.3 (including) 3.3 (including)
Freebsd Freebsd 3.4 (including) 3.4 (including)
Freebsd Freebsd 3.5 (including) 3.5 (including)
Freebsd Freebsd 4.0 (including) 4.0 (including)
Netbsd Netbsd 1.4 (including) 1.4 (including)
Netbsd Netbsd 1.4.1 (including) 1.4.1 (including)
Netbsd Netbsd 1.4.2 (including) 1.4.2 (including)
Openbsd Openbsd 2.3 (including) 2.3 (including)
Openbsd Openbsd 2.4 (including) 2.4 (including)
Openbsd Openbsd 2.5 (including) 2.5 (including)
Openbsd Openbsd 2.6 (including) 2.6 (including)
Openbsd Openbsd 2.7 (including) 2.7 (including)

References