CVE
- Id
- 3721
- CVE No.
- CVE-2001-0915
- Status
- Candidate
- Description
- Format string vulnerability in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via format specifiers in the check argument of a shell definition.
- Phase
- Modified (20050703)
- Votes
- ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall
- Comments
- Frech> XF:pmake-shell-format-string(7602) | Baker> A check of the latest version of pmake, version 2.1.36 reveals that the author lists the format string error as having been corrected. | ftp://ftp.icsi.berkeley.edu/pub/speech/stolcke/software/pmake-2.1.36.tar.Z | | This should be sufficient for vendor acknowledgement.