Vulnerability Name: | CVE-2000-0993 (CCN-5339) | ||||||||
Assigned: | 2000-10-04 | ||||||||
Published: | 2000-10-04 | ||||||||
Updated: | 2017-10-10 | ||||||||
Summary: | Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: FREEBSD Type: UNKNOWN FreeBSD-SA-00:58 Source: NETBSD Type: UNKNOWN NetBSD-SA2000-015 Source: CCN Type: BugTraq Mailing List, Tue Oct 03 2000 - 19:08:24 CDT OpenBSD Security Advisory Source: CCN Type: FreeBSD Security Advisory FreeBSD-SA-00:58 chpass family contains local root vulnerability Source: CCN Type: NetBSD Security Advisory 2000-015 format-string bugs in passwd/libutil Source: MITRE Type: CNA CVE-2000-0993 Source: BUGTRAQ Type: UNKNOWN 20001004 Re: OpenBSD Security Advisory Source: CCN Type: US-CERT VU#369427 Format string vulnerability in libutil pw_error(3) function Source: CCN Type: OpenBSD Security Advisory, October 3, 2000 A format string vulnerability exists in the pw_error(3) function. Source: OPENBSD Type: UNKNOWN 20001003 A format string vulnerability exists in the pw_error(3) function. Source: CCN Type: OSVDB ID: 1587 Multiple BSD libutil pw_error() Format String Privilege Escalation Source: BID Type: Exploit, Patch, Vendor Advisory 1744 Source: CCN Type: BID-1744 Multiple Vendor BSD libutil pw_error() Format String Vulnerability Source: XF Type: UNKNOWN bsd-libutil-format(5339) Source: XF Type: UNKNOWN bsd-libutil-format(5339) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |