CVE
- Id
- 2487
- CVE No.
- CVE-2000-0918
- Status
- Candidate
- Description
- Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters.
- Phase
- Proposed (20001129)
- Votes
- ACCEPT(2) Baker, Mell | NOOP(2) Cole, Wall | REVIEWING(1) Christey
- Comments
- Christey> May be a duplicate of CVE-2000-0373, but the ref"s in that CVE | are vague. I suspect this *isn"t* a duplicate because this is | a format string problem. | Baker> I think it is sufficiently different from 2000-0373.