CVE-2000-0994: High severity OpenBSD OpenBSD vulnerability
Published Dec 19, 2000
·Updated
Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.
Affected Software
5 affected components
OpenBSD OpenBSD=2.7
OpenBSD OpenBSD=2.4
OpenBSD OpenBSD=2.6
OpenBSD OpenBSD=2.5
OpenBSD OpenBSD=2.3
Remediation
Event History
Dec 19, 2000
CVE Published
05:00 AM
Jan 22, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0994?
CVE-2000-0994 has been classified as a high-severity vulnerability because it allows local users to gain root privileges.
2
How do I fix CVE-2000-0994?
To fix CVE-2000-0994, upgrade to a patched version of OpenBSD that addresses this format string vulnerability.
3
Which versions of OpenBSD are affected by CVE-2000-0994?
CVE-2000-0994 affects OpenBSD versions 2.3 through 2.7.
4
Can CVE-2000-0994 be exploited remotely?
No, CVE-2000-0994 can only be exploited locally by authenticated users on the affected system.
5
What is the impact of CVE-2000-0994 on system security?
The impact of CVE-2000-0994 is severe as it can allow a local user to execute arbitrary code with root privileges.