Vulnerability Name: | CVE-2000-1040 (CCN-5394) | ||||||||
Assigned: | 2000-10-18 | ||||||||
Published: | 2000-10-18 | ||||||||
Updated: | 2017-10-10 | ||||||||
Summary: | Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a denial of service. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Caldera International, Inc. Security Advisory CSSA-2000-039.0 security problems in ypbind Source: BUGTRAQ Type: UNKNOWN 20001025 Immunix OS Security Update for ypbind package Source: CCN Type: BugTraq Mailing List, Wed Oct 25 2000 - 03:16:06 CDT Immunix OS Security Update for ypbind package Source: BUGTRAQ Type: UNKNOWN 20001030 Trustix Security Advisory - ping gnupg ypbind Source: CCN Type: BugTraq Mailing List, Mon Oct 30 2000 - 08:43:28 CST Trustix Security Advisory - ping gnupg ypbind Source: SUSE Type: UNKNOWN SuSE-SA:2000:042 Source: MITRE Type: CNA CVE-2000-1040 Source: MITRE Type: CNA CVE-2000-1044 Source: CCN Type: RHSA-2000-086 ypbind for Red Hat Linux 5.x Source: CALDERA Type: UNKNOWN CSSA-2000-039.0 Source: CCN Type: CIAC Information Bulletin L-009 Red Hat Linux "ypbind" Vulnerability Source: DEBIAN Type: UNKNOWN 20001014 nis: local exploit Source: DEBIAN Type: Debian Security Advisory 20001014 nis: local exploit Source: CCN Type: Linux-Mandrake Security Update Advisory MDKSA-2000:064 ypbind and ypserv Source: MANDRAKE Type: UNKNOWN MDKSA-2000:064 Source: CCN Type: OSVDB ID: 1618 ypbind printf() Format String Source: CCN Type: OSVDB ID: 7197 SuSE Linux ypbind-mt Format String Privilege Escalation Source: REDHAT Type: UNKNOWN RHSA-2000:086 Source: BID Type: Patch, Vendor Advisory 1820 Source: CCN Type: BID-1820 S.u.S.E. ypbind-mt Format String Vulnerability Source: CCN Type: BID-1824 Linux ypbind Local Format String Vulnerability Source: CCN Type: SuSE Security Announcement SuSE-SA:2000:042 ypbind/ypclient Source: XF Type: UNKNOWN ypbind-printf-format-string(5394) Source: XF Type: UNKNOWN ypbind-printf-format-string(5394) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |