CVE-2000-0844: Critical severity SGI IRIX vulnerability

Published Nov 14, 2000
·
Updated

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.

Affected Software

74 affected components
SGI IRIX=6.5.6
SGI IRIX=6.5.3f
SGI IRIX=6.5.1
Conectiva Linux=4.2
Conectiva Linux=4.1
Conectiva Linux=5.1
Immunix Immunix=6.2
SGI IRIX=6.4
SGI IRIX=6.5.2m
SGI IRIX=6.5.3
SGI IRIX=6.5.3m
SGI IRIX=6.5.8
Conectiva Linux=4.0es
Caldera Openlinux Ebuilder=3.0
SGI IRIX=6.5.4
SGI IRIX=6.3
Conectiva Linux=5.0
SGI IRIX=6.5
SGI IRIX=6.5.7
SGI IRIX=6.2
Conectiva Linux=4.0
SUSE SuSE Linux=6.2
IBM AIX=4.3.2
IBM AIX=4.3
Sun SunOS=5.3
Debian Debian Linux=2.3
Trustix Secure Linux=1.1
IBM AIX=4.2.1
redhat Linux=5.1
Debian Debian Linux=2.2
Debian Debian Linux=2.1
IBM AIX=3.2.5
Mandrakesoft Mandrake Linux=7.0
redhat Linux=6.1
IBM AIX=3.2.4
Slackware Slackware Linux=7.1
IBM AIX=4.1.4
IBM AIX=4.2
IBM AIX=4.1.5
redhat Linux=6.2
redhat Linux=5.0
Mandrakesoft Mandrake Linux=7.1
Trustix Secure Linux=1.0
Sun SunOS=5.7
Sun SunOS=5.5
Sun SunOS=5.8
Turbolinux Turbolinux=6.0.1
Caldera OpenLinux
redhat Linux=5.2
Turbolinux Turbolinux=6.0
Turbolinux Turbolinux=6.0.2
Slackware Slackware Linux=7.0
SUSE SuSE Linux=6.1
Caldera Openlinux Eserver=2.3
IBM AIX=4.0
IBM AIX=4.1.1
Turbolinux Turbolinux=6.0.4
Sun SunOS=5.4
SUSE SuSE Linux=7.0
SUSE SuSE Linux=6.3
Sun SunOS=5.5.1
IBM AIX=4.1.2
SUSE SuSE Linux=6.4
Debian Debian Linux=2.0
IBM AIX=4.3.1
Turbolinux Turbolinux=6.0.3
redhat Linux=6.0
IBM AIX=4.1
Sun SunOS=5.0
IBM AIX=4.1.3
IBM AIX=3.2
Sun Solaris=2.6
Sun SunOS=5.1
Sun SunOS=5.2

Event History

Nov 14, 2000
CVE Published
05:00 AM
Jan 22, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2000-0844?

CVE-2000-0844 has been classified as a medium severity vulnerability due to its potential to allow local attackers to execute arbitrary commands.

2

How do I fix CVE-2000-0844?

To fix CVE-2000-0844, users should upgrade to the latest version of the affected software that contains the necessary patches.

3

What systems are affected by CVE-2000-0844?

CVE-2000-0844 affects various versions of SGI IRIX, Conectiva Linux, Caldera OpenLinux, IBM AIX, and several other Unix-like operating systems.

4

How does CVE-2000-0844 exploit user-injected format strings?

CVE-2000-0844 exploits vulnerabilities in functions like gettext and catopen by not properly cleansing user-injected format strings.

5

Is CVE-2000-0844 still a threat today?

While CVE-2000-0844 is older, it remains a threat if affected systems have not been patched or upgraded.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203