CVE-2000-0844
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
- Affected products
- Aix, Debian, Immunix, Irix, Linux, Mandrake Linux, Openlinux, Openlinux Ebuilder
- Caldera Openlinux Ebuilder
- = 3.0
- Immunix
- = 6.2
- Conectiva Linux
- = 4.0, 4.0es, 4.1, 4.2, 5.0, 5.1
- Sgi Irix
- = 6.2, 6.3, 6.4, 6.5, 6.5.1, 6.5.2m, 6.5.3, 6.5.3f, 6.5.3m, 6.5.4, 6.5.6, 6.5.7, 6.5.8
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 15.3% (97th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2001-01-22
CVE-2000-0844 at NVD
11 known exploits for CVE-2000-0844
Proof-of-concept code and exploit modules indexed by Sploitus
GLIBC locale - Format Strings
GLIBC locale - bug mount
GLIBC - '/bin/su' Local Privilege Escalation
Solaris 2.6/7.0 - 'locale' Format Strings noexec stack Overflow
Solaris/SPARC 2.7 / 7 locale - Format String
Solaris 2.6/7.0 /locale - Subsystem Format String
Solaris 2.6/7.0 'eject' locale - Subsystem Format String
RedHat 6 GLIBC/locale - Subsystem Format String
Immunix OS 6.2 - LC glibc format string
Libc locale - Local Privilege Escalation (1)
Libc locale - Local Privilege Escalation (2)