Buffer overflow in catopen() function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to gain root privileges via a long environmental variable.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Freebsd | Freebsd | 3.0 (including) | 3.0 (including) | 
| Freebsd | Freebsd | 3.1 (including) | 3.1 (including) | 
| Freebsd | Freebsd | 3.2 (including) | 3.2 (including) | 
| Freebsd | Freebsd | 3.3 (including) | 3.3 (including) | 
| Freebsd | Freebsd | 3.4 (including) | 3.4 (including) | 
| Freebsd | Freebsd | 3.5 (including) | 3.5 (including) | 
| Freebsd | Freebsd | 3.5.1 (including) | 3.5.1 (including) | 
| Freebsd | Freebsd | 4.0 (including) | 4.0 (including) | 
| Freebsd | Freebsd | 4.1 (including) | 4.1 (including) | 
| Freebsd | Freebsd | 4.1.1 (including) | 4.1.1 (including) | 
| Freebsd | Freebsd | 4.2 (including) | 4.2 (including) | 
| Freebsd | Freebsd | 5.0 (including) | 5.0 (including) |