First published: Thu Sep 21 2000(Updated: )
The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Mailman | =2.0-beta3 | |
GNU Mailman | =2.0-beta4 | |
Conectiva Linux | =4.1 | |
Conectiva Linux | =4.2 | |
Conectiva Linux | =5.0 | |
Conectiva Linux | =5.1 | |
Red Hat Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0701 has a moderate severity rating due to its potential to allow local users to gain elevated privileges.
To fix CVE-2000-0701, update to a patched version of Mailman that properly sanitizes format strings.
CVE-2000-0701 affects Mailman 2.0beta3 and 2.0beta4, along with certain versions of Conectiva Linux and Red Hat Linux.
Local users on systems running vulnerable versions of Mailman may be impacted by CVE-2000-0701.
CVE-2000-0701 is a format string vulnerability that can be exploited to elevate user privileges.