CVE-2000-1004: Medium severity OpenBSD OpenBSD vulnerability
Published Dec 11, 2000
·Updated
Format string vulnerability in OpenBSD photurisd allows local users to execute arbitrary commands via a configuration file directory name that contains formatting characters.
Affected Software
5 affected components
OpenBSD OpenBSD=2.7
OpenBSD OpenBSD=2.4
OpenBSD OpenBSD=2.6
OpenBSD OpenBSD=2.5
OpenBSD OpenBSD=2.3
Event History
Dec 11, 2000
CVE Published
05:00 AM
Jan 22, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-1004?
CVE-2000-1004 is classified as a high severity vulnerability due to its potential to allow local users to execute arbitrary commands.
2
How do I fix CVE-2000-1004?
To fix CVE-2000-1004, update the OpenBSD system to the latest version or apply any available patches addressing the format string vulnerability.
3
Which versions of OpenBSD are affected by CVE-2000-1004?
CVE-2000-1004 affects OpenBSD versions 2.3 through 2.7.
4
What types of systems can be impacted by CVE-2000-1004?
Local systems running vulnerable versions of OpenBSD's photurisd service can be impacted by CVE-2000-1004.
5
Can CVE-2000-1004 be exploited remotely?
CVE-2000-1004 cannot be exploited remotely as it requires local access to execute commands.