Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2000-11-14 05:00
Updated : 2026-06-16 21:52
NVD link : CVE-2000-0844
Mitre link : CVE-2000-0844
CVE.ORG link : CVE-2000-0844
JSON object : View
Products Affected
trustix
- secure_linux
caldera
- openlinux_ebuilder
- openlinux_eserver
- openlinux
sgi
- irix
immunix
- immunix
debian
- debian_linux
conectiva
- linux
mandrakesoft
- mandrake_linux
redhat
- linux
sun
- solaris
- sunos
ibm
- aix
suse
- suse_linux
slackware
- slackware_linux
turbolinux
- turbolinux
CWE
CWE-264
Permissions, Privileges, and Access Controls
