CVE Vulnerabilities

CVE-2000-1012

Published: Dec 11, 2000 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The catopen function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd 3.0 (including) 3.0 (including)
Freebsd Freebsd 3.1 (including) 3.1 (including)
Freebsd Freebsd 3.2 (including) 3.2 (including)
Freebsd Freebsd 3.3 (including) 3.3 (including)
Freebsd Freebsd 3.4 (including) 3.4 (including)
Freebsd Freebsd 3.5 (including) 3.5 (including)
Freebsd Freebsd 3.5.1 (including) 3.5.1 (including)
Freebsd Freebsd 4.0 (including) 4.0 (including)
Freebsd Freebsd 4.1 (including) 4.1 (including)
Freebsd Freebsd 4.1.1 (including) 4.1.1 (including)
Freebsd Freebsd 4.2 (including) 4.2 (including)
Freebsd Freebsd 5.0 (including) 5.0 (including)

References