First published: Tue Dec 19 2000(Updated: )
Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CFEngine | =1.5 | |
CFEngine | =1.5.3-4 | |
CFEngine | =1.6-a10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0947 is considered a high severity vulnerability due to its potential to allow attackers to execute arbitrary commands.
To fix CVE-2000-0947, upgrade to GNU CFEngine version 1.6.0a11 or later.
CVE-2000-0947 affects GNU CFEngine versions 1.5, 1.5.3-4, and 1.6-a10.
CVE-2000-0947 is a format string vulnerability that allows command execution.
Yes, CVE-2000-0947 can potentially be exploited remotely by sending specially crafted CAUTH commands.