CVE Vulnerabilities

CVE-2000-0994

Published: Dec 19, 2000 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.

Affected Software

Name Vendor Start Version End Version
Openbsd Openbsd 2.3 (including) 2.3 (including)
Openbsd Openbsd 2.4 (including) 2.4 (including)
Openbsd Openbsd 2.5 (including) 2.5 (including)
Openbsd Openbsd 2.6 (including) 2.6 (including)
Openbsd Openbsd 2.7 (including) 2.7 (including)

References