Back to search
CVE-2000-0844
Published: Jan 22, 2001
Modified: Aug 8, 2024
PUBLISHED
Description
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2000:057
vendor-advisory
x_refsource_REDHAT
20000906 glibc locale security problem
vendor-advisory
x_refsource_SUSE
20000902 Conectiva Linux Security Announcement - glibc
mailing-list
x_refsource_BUGTRAQ
SSRT0689U
vendor-advisory
x_refsource_COMPAQ
TLSA2000020-1
vendor-advisory
x_refsource_TURBO
20000902 glibc: local root exploit
vendor-advisory
x_refsource_DEBIAN
20000904 UNIX locale format string vulnerability
mailing-list
x_refsource_BUGTRAQ
IY13753
vendor-advisory
x_refsource_AIXAPAR
1634
vdb-entry
x_refsource_BID
CSSA-2000-030.0
vendor-advisory
x_refsource_CALDERA
unix-locale-format-string(5176)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now