First published: Tue Dec 19 2000(Updated: )
Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenBSD | =2.7 | |
OpenBSD | =2.4 | |
OpenBSD | =2.6 | |
OpenBSD | =2.5 | |
OpenBSD | =2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0994 has been classified as a high-severity vulnerability because it allows local users to gain root privileges.
To fix CVE-2000-0994, upgrade to a patched version of OpenBSD that addresses this format string vulnerability.
CVE-2000-0994 affects OpenBSD versions 2.3 through 2.7.
No, CVE-2000-0994 can only be exploited locally by authenticated users on the affected system.
The impact of CVE-2000-0994 is severe as it can allow a local user to execute arbitrary code with root privileges.