CVE Vulnerabilities

CVE-2000-1013

Published: Dec 11, 2000 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd 3.0 (including) 3.0 (including)
Freebsd Freebsd 3.1 (including) 3.1 (including)
Freebsd Freebsd 3.2 (including) 3.2 (including)
Freebsd Freebsd 3.3 (including) 3.3 (including)
Freebsd Freebsd 3.4 (including) 3.4 (including)
Freebsd Freebsd 3.5 (including) 3.5 (including)
Freebsd Freebsd 3.5.1 (including) 3.5.1 (including)
Freebsd Freebsd 4.0 (including) 4.0 (including)
Freebsd Freebsd 4.1 (including) 4.1 (including)
Freebsd Freebsd 4.1.1 (including) 4.1.1 (including)
Freebsd Freebsd 4.2 (including) 4.2 (including)
Freebsd Freebsd 5.0 (including) 5.0 (including)

References