10
CVSSv2

CVE-2000-0844

Published: 14/11/2000 Updated: 30/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local malicious users to execute arbitrary commands via functions such as gettext and catopen.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sgi irix 6.5.6

sgi irix 6.5.3f

sgi irix 6.5.1

conectiva linux 4.2

conectiva linux 4.1

conectiva linux 5.1

immunix immunix 6.2

sgi irix 6.4

sgi irix 6.5.2m

sgi irix 6.5.3

sgi irix 6.5.3m

sgi irix 6.5.8

conectiva linux 4.0es

caldera openlinux ebuilder 3.0

sgi irix 6.5.4

sgi irix 6.3

conectiva linux 5.0

sgi irix 6.5

sgi irix 6.5.7

sgi irix 6.2

conectiva linux 4.0

suse suse linux 6.2

ibm aix 4.3.2

ibm aix 4.3

sun sunos 5.3

debian debian linux 2.3

trustix secure linux 1.1

ibm aix 4.2.1

redhat linux 5.1

debian debian linux 2.2

debian debian linux 2.1

ibm aix 3.2.5

mandrakesoft mandrake linux 7.0

redhat linux 6.1

ibm aix 3.2.4

slackware slackware linux 7.1

ibm aix 4.1.4

ibm aix 4.2

ibm aix 4.1.5

redhat linux 6.2

redhat linux 5.0

mandrakesoft mandrake linux 7.1

trustix secure linux 1.0

sun sunos 5.7

sun sunos 5.5

sun sunos 5.8

turbolinux turbolinux 6.0.1

caldera openlinux

redhat linux 5.2

turbolinux turbolinux 6.0

turbolinux turbolinux 6.0.2

slackware slackware linux 7.0

suse suse linux 6.1

caldera openlinux eserver 2.3

ibm aix 4.0

ibm aix 4.1.1

turbolinux turbolinux 6.0.4

sun sunos 5.4

suse suse linux 7.0

suse suse linux 6.3

sun sunos 5.5.1

ibm aix 4.1.2

suse suse linux 6.4

debian debian linux 2.0

ibm aix 4.3.1

turbolinux turbolinux 6.0.3

redhat linux 6.0

ibm aix 4.1

sun sunos 5.0

ibm aix 4.1.3

ibm aix 3.2

sun solaris 2.6

sun sunos 5.1

sun sunos 5.2

Exploits

/* source: wwwsecurityfocuscom/bid/1634/info nectiva 4x/5x,Debian 2x,IBM AIX 3x/4x,Mandrake 7,RedHat 5x/6x,IRIX 6x, Solaris 2x/7/8,Turbolinux 6x,Wirex Immunix OS 62 Locale Subsystem Format String Many UNIX operating systems provide internationalization support according to the X/Open XPG3, XPG4 and Sun/Uniforum specificatio ...
/* source: wwwsecurityfocuscom/bid/1634/info nectiva 4x/5x,Debian 2x,IBM AIX 3x/4x,Mandrake 7,RedHat 5x/6x,IRIX 6x, Solaris 2x/7/8,Turbolinux 6x,Wirex Immunix OS 62 Locale Subsystem Format String Many UNIX operating systems provide internationalization support according to the X/Open XPG3, XPG4 and Sun/Uniforum specificat ...
/* source: wwwsecurityfocuscom/bid/1634/info nectiva 4x/5x,Debian 2x,IBM AIX 3x/4x,Mandrake 7,RedHat 5x/6x,IRIX 6x, Solaris 2x/7/8,Turbolinux 6x,Wirex Immunix OS 62 Locale Subsystem Format String Many UNIX operating systems provide internationalization support according to the X/Open XPG3, XPG4 and Sun/Uniforum specifications ...
/* source: wwwsecurityfocuscom/bid/1634/info ectiva 4x/5x,Debian 2x,IBM AIX 3x/4x,Mandrake 7,RedHat 5x/6x,IRIX 6x, Solaris 2x/7/8,Turbolinux 6x,Wirex Immunix OS 62 Locale Subsystem Format String Many UNIX operating systems provide internationalization support according to the X/Open XPG3, XPG4 and Sun/Uniforum specifications u ...
/* source: wwwsecurityfocuscom/bid/1634/info ectiva 4x/5x,Debian 2x,IBM AIX 3x/4x,Mandrake 7,RedHat 5x/6x,IRIX 6x, Solaris 2x/7/8,Turbolinux 6x,Wirex Immunix OS 62 Locale Subsystem Format String Many UNIX operating systems provide internationalization support according to the X/Open XPG3, XPG4 and Sun/Uniforum specifi ...
/* * mount exploit for glibc locale bug * tested on redhat 62 and slackware 70 and debian 22 * * Debian 22 (mount-210f) : /mnt -n 136 -a 0x080589a0 -i 192 * Redhat 62 (mount-210f) : /mnt -n 114 -a 0x080565dc -i 112 * compiled on rh 62 (mount-210m): /mnt -n 114 -a 0x08059218 -i 112 * * ...
/* Exploit for the locale format string vulnerability in Solaris/SPARC 27 / 7 Based on the exploit by Warning3 <warning3@nsfocuscom> For additional information see wwwphreedomorg/solar/locale_soltxt By Solar Eclipse <solareclipse@phreedomorg> Assistant Editor, Phreedom Magazine wwwphreedomorg ...
/* source: wwwsecurityfocuscom/bid/1634/info Conectiva 4x/5x,Debian 2x,IBM AIX 3x/4x,Mandrake 7,RedHat 5x/6x,IRIX 6x, Solaris 2x/7/8,Turbolinux 6x,Wirex Immunix OS 62 Locale Subsystem Format String Many UNIX operating systems provide internationalization support according to the X/Open XPG3, XPG4 and Sun/Uniforum specification ...
/* * exploit for locale subsystem format strings bug In Solaris with noexec stack * Tested in Solaris 26/70 (If it wont work, try adjust retloc offset eg * /ex -o -4 ) * * $gcc -o ex exc `ldd /usr/bin/passwd|sed -e 's/^lib\([_0-9a-zA-Z]*\)\so*/-l\1/'` * usages: /ex -h * * Thanks for Ivan Arce <iarce@core-sdicom> who foun ...
/* suc by xp, modified by logikal@efnet - tested on redhat 5 -> 7 */ #include <stdioh> #include <stdlibh> #include <sys/typesh> #include <sys/stath> #include <fcntlh> #include <stringh> #include <getopth> #include <direnth> char *shellcode = "\x31\xc0\x83\xc0\x17\x31\xdb\xcd\x80\xeb" "\x3 ...
/* * * Working exploit for glibc executing /bin/su * * To exploit this i have used a technique that * overwrites the dtors section of /bin/su program * with the address of the shellcode, so, the program * executes it when main returns or exit() is called * * Thanks a lot to rwxrwxrwx <jmbr@qualyscom> for * explaining me th ...