CVE-2000-0467: Buffer Overflow
Buffer overflow in Linux splitvt 1.6.3 and earlier allows local users to gain root privileges via a long password in the screen locking function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Split VT (splitvt)from your environment.Uninstall Split VT (splitvt) 1.6.3 and earlier from affected systems until a security patch or fixed version is available.
- Configuration
Disable the screen locking function in Split VT to prevent exploitation via a long password in the screen locking function.
Split VT (splitvt) screen locking = disabled - Compensating control
Restrict local access and privileges: limit who can log in locally or access console/tty devices and remove unneeded local user accounts to reduce the risk from local privilege escalation.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0467?
CVE-2000-0467 is considered a critical vulnerability as it allows local users to gain root privileges.
How do I fix CVE-2000-0467?
To fix CVE-2000-0467, update splitvt to version 1.6.4 or later where the buffer overflow vulnerability has been addressed.
Who is affected by CVE-2000-0467?
CVE-2000-0467 affects local users of Linux operating systems that have splitvt version 1.6.3 or earlier installed.
What causes CVE-2000-0467?
CVE-2000-0467 is caused by a buffer overflow in the screen locking function of splitvt when it processes a long password.
Can CVE-2000-0467 be exploited remotely?
CVE-2000-0467 cannot be exploited remotely; it requires local access to the vulnerable system.