CVE
- Id
- 2413
- CVE No.
- CVE-2000-0844
- Status
- Entry
- Description
- Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
- Phase
- Votes
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
8934 | 2413 | CVE-2000-0844 | BUGTRAQ:20000904 UNIX locale format string vulnerability | View |
8935 | 2413 | CVE-2000-0844 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0457.html | View |
8936 | 2413 | CVE-2000-0844 | DEBIAN:20000902 glibc: local root exploit | View |
8937 | 2413 | CVE-2000-0844 | URL:http://www.debian.org/security/2000/20000902 | View |
8938 | 2413 | CVE-2000-0844 | CALDERA:CSSA-2000-030.0 | View |
8939 | 2413 | CVE-2000-0844 | URL:http://www.calderasystems.com/support/security/advisories/CSSA-2000-030.0.txt | View |
8940 | 2413 | CVE-2000-0844 | REDHAT:RHSA-2000:057 | View |
8941 | 2413 | CVE-2000-0844 | URL:http://www.redhat.com/support/errata/RHSA-2000-057.html | View |
8942 | 2413 | CVE-2000-0844 | SUSE:20000906 glibc locale security problem | View |
8943 | 2413 | CVE-2000-0844 | URL:http://www.novell.com/linux/security/advisories/adv5_draht_glibc_txt.html | View |
8944 | 2413 | CVE-2000-0844 | TURBO:TLSA2000020-1 | View |
8945 | 2413 | CVE-2000-0844 | URL:http://www.turbolinux.com/pipermail/tl-security-announce/2000-September/000020.html | View |
8946 | 2413 | CVE-2000-0844 | AIXAPAR:IY13753 | View |
8947 | 2413 | CVE-2000-0844 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0427.html | View |
8948 | 2413 | CVE-2000-0844 | COMPAQ:SSRT0689U | View |
8949 | 2413 | CVE-2000-0844 | URL:http://archives.neohapsis.com/archives/tru64/2000-q4/0000.html | View |
8950 | 2413 | CVE-2000-0844 | SGI:20000901-01-P | View |
8951 | 2413 | CVE-2000-0844 | URL:ftp://patches.sgi.com/support/free/security/advisories/20000901-01-P | View |
8952 | 2413 | CVE-2000-0844 | BUGTRAQ:20000902 Conectiva Linux Security Announcement - glibc | View |
8953 | 2413 | CVE-2000-0844 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0436.html | View |
8954 | 2413 | CVE-2000-0844 | BID:1634 | View |
8955 | 2413 | CVE-2000-0844 | URL:http://www.securityfocus.com/bid/1634 | View |
8956 | 2413 | CVE-2000-0844 | XF:unix-locale-format-string(5176) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
64284 | JVNDB-2000-000064 | 複数ベンダのロケールサブシステムにおけるフォーマットストリングの脆弱性 | UNIX OS のロケールサブシステムには、メッセージオブジェクトファイルのサブディレクトリ名を特殊な形式で指定することにより、フォーマットストリングの脆弱性が存在します。 | CVE-2000-0844 | 2413 | 10 | http://jvndb.jvn.jp/ja/contents/2000/JVNDB-2000-000064.html | View |