CVE Vulnerabilities

CVE-2000-1010

Published: Dec 11, 2000 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters.

Affected Software

Name Vendor Start Version End Version
Openbsd Openbsd 2.3 (including) 2.3 (including)
Openbsd Openbsd 2.4 (including) 2.4 (including)
Openbsd Openbsd 2.5 (including) 2.5 (including)
Openbsd Openbsd 2.6 (including) 2.6 (including)
Openbsd Openbsd 2.7 (including) 2.7 (including)
Linux Redhat 5.0 (including) 5.0 (including)
Linux Redhat 5.1 (including) 5.1 (including)
Linux Redhat 5.2 (including) 5.2 (including)

References