10
CVSSv2

CVE-2000-0844

Published: 14/11/2000 Updated: 30/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local malicious users to execute arbitrary commands via functions such as gettext and catopen.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

conectiva linux 4.0es

conectiva linux 4.1

sgi irix 6.5

sgi irix 6.5.1

sgi irix 6.5.2m

conectiva linux 4.2

conectiva linux 5.0

sgi irix 6.5.3

sgi irix 6.5.3f

immunix immunix 6.2

conectiva linux 4.0

sgi irix 6.3

sgi irix 6.4

sgi irix 6.5.6

sgi irix 6.5.7

sgi irix 6.5.8

caldera openlinux ebuilder 3.0

conectiva linux 5.1

sgi irix 6.2

sgi irix 6.5.3m

sgi irix 6.5.4

caldera openlinux

caldera openlinux eserver 2.3

ibm aix 3.2.5

ibm aix 4.0

ibm aix 4.2.1

ibm aix 4.3

redhat linux 5.2

redhat linux 6.0

sun sunos 5.2

sun sunos 5.3

suse suse linux 6.2

suse suse linux 6.3

turbolinux turbolinux 6.0.2

debian debian linux 2.2

debian debian linux 2.3

ibm aix 4.1.2

ibm aix 4.1.3

ibm aix 4.1.4

mandrakesoft mandrake linux 7.0

mandrakesoft mandrake linux 7.1

slackware slackware linux 7.0

slackware slackware linux 7.1

sun solaris 2.6

sun sunos 5.7

trustix secure linux 1.0

trustix secure linux 1.1

ibm aix 3.2

ibm aix 3.2.4

ibm aix 4.1.5

ibm aix 4.2

redhat linux 5.0

redhat linux 5.1

sun sunos 5.0

sun sunos 5.1

sun sunos 5.8

suse suse linux 6.1

turbolinux turbolinux 6.0

turbolinux turbolinux 6.0.1

turbolinux turbolinux 6.0.3

debian debian linux 2.0

debian debian linux 2.1

ibm aix 4.1

ibm aix 4.1.1

ibm aix 4.3.1

ibm aix 4.3.2

redhat linux 6.1

redhat linux 6.2

sun sunos 5.4

sun sunos 5.5

sun sunos 5.5.1

suse suse linux 6.4

suse suse linux 7.0

turbolinux turbolinux 6.0.4

Exploits

/* source: wwwsecurityfocuscom/bid/1634/info nectiva 4x/5x,Debian 2x,IBM AIX 3x/4x,Mandrake 7,RedHat 5x/6x,IRIX 6x, Solaris 2x/7/8,Turbolinux 6x,Wirex Immunix OS 62 Locale Subsystem Format String Many UNIX operating systems provide internationalization support according to the X/Open XPG3, XPG4 and Sun/Uniforum specificat ...
/* source: wwwsecurityfocuscom/bid/1634/info nectiva 4x/5x,Debian 2x,IBM AIX 3x/4x,Mandrake 7,RedHat 5x/6x,IRIX 6x, Solaris 2x/7/8,Turbolinux 6x,Wirex Immunix OS 62 Locale Subsystem Format String Many UNIX operating systems provide internationalization support according to the X/Open XPG3, XPG4 and Sun/Uniforum specifications ...
/* source: wwwsecurityfocuscom/bid/1634/info nectiva 4x/5x,Debian 2x,IBM AIX 3x/4x,Mandrake 7,RedHat 5x/6x,IRIX 6x, Solaris 2x/7/8,Turbolinux 6x,Wirex Immunix OS 62 Locale Subsystem Format String Many UNIX operating systems provide internationalization support according to the X/Open XPG3, XPG4 and Sun/Uniforum specificatio ...
/* source: wwwsecurityfocuscom/bid/1634/info ectiva 4x/5x,Debian 2x,IBM AIX 3x/4x,Mandrake 7,RedHat 5x/6x,IRIX 6x, Solaris 2x/7/8,Turbolinux 6x,Wirex Immunix OS 62 Locale Subsystem Format String Many UNIX operating systems provide internationalization support according to the X/Open XPG3, XPG4 and Sun/Uniforum specifications u ...
/* source: wwwsecurityfocuscom/bid/1634/info ectiva 4x/5x,Debian 2x,IBM AIX 3x/4x,Mandrake 7,RedHat 5x/6x,IRIX 6x, Solaris 2x/7/8,Turbolinux 6x,Wirex Immunix OS 62 Locale Subsystem Format String Many UNIX operating systems provide internationalization support according to the X/Open XPG3, XPG4 and Sun/Uniforum specifi ...
/* source: wwwsecurityfocuscom/bid/1634/info Conectiva 4x/5x,Debian 2x,IBM AIX 3x/4x,Mandrake 7,RedHat 5x/6x,IRIX 6x, Solaris 2x/7/8,Turbolinux 6x,Wirex Immunix OS 62 Locale Subsystem Format String Many UNIX operating systems provide internationalization support according to the X/Open XPG3, XPG4 and Sun/Uniforum specification ...
/* Exploit for the locale format string vulnerability in Solaris/SPARC 27 / 7 Based on the exploit by Warning3 <warning3@nsfocuscom> For additional information see wwwphreedomorg/solar/locale_soltxt By Solar Eclipse <solareclipse@phreedomorg> Assistant Editor, Phreedom Magazine wwwphreedomorg ...
/* * mount exploit for glibc locale bug * tested on redhat 62 and slackware 70 and debian 22 * * Debian 22 (mount-210f) : /mnt -n 136 -a 0x080589a0 -i 192 * Redhat 62 (mount-210f) : /mnt -n 114 -a 0x080565dc -i 112 * compiled on rh 62 (mount-210m): /mnt -n 114 -a 0x08059218 -i 112 * * ...
/* * exploit for locale subsystem format strings bug In Solaris with noexec stack * Tested in Solaris 26/70 (If it wont work, try adjust retloc offset eg * /ex -o -4 ) * * $gcc -o ex exc `ldd /usr/bin/passwd|sed -e 's/^lib\([_0-9a-zA-Z]*\)\so*/-l\1/'` * usages: /ex -h * * Thanks for Ivan Arce <iarce@core-sdicom> who foun ...
/* suc by xp, modified by logikal@efnet - tested on redhat 5 -> 7 */ #include <stdioh> #include <stdlibh> #include <sys/typesh> #include <sys/stath> #include <fcntlh> #include <stringh> #include <getopth> #include <direnth> char *shellcode = "\x31\xc0\x83\xc0\x17\x31\xdb\xcd\x80\xeb" "\x3 ...
/* * * Working exploit for glibc executing /bin/su * * To exploit this i have used a technique that * overwrites the dtors section of /bin/su program * with the address of the shellcode, so, the program * executes it when main returns or exit() is called * * Thanks a lot to rwxrwxrwx <jmbr@qualyscom> for * explaining me th ...