CVE-2000-0947: Critical severity gnu cfengine vulnerability
Published Dec 19, 2000
·Updated
Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.
Affected Software
3 affected components
GNU CFEngine=1.5
GNU CFEngine=1.5.3-4
GNU CFEngine=1.6-a10
Remediation
Patch Available
Event History
Dec 19, 2000
CVE Published
05:00 AM
Jan 22, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0947?
CVE-2000-0947 is considered a high severity vulnerability due to its potential to allow attackers to execute arbitrary commands.
2
How do I fix CVE-2000-0947?
To fix CVE-2000-0947, upgrade to GNU CFEngine version 1.6.0a11 or later.
3
What software is affected by CVE-2000-0947?
CVE-2000-0947 affects GNU CFEngine versions 1.5, 1.5.3-4, and 1.6-a10.
4
What type of vulnerability is CVE-2000-0947?
CVE-2000-0947 is a format string vulnerability that allows command execution.
5
Can CVE-2000-0947 be exploited remotely?
Yes, CVE-2000-0947 can potentially be exploited remotely by sending specially crafted CAUTH commands.