7.2
CVSSv2

CVE-2000-0994

Published: 19/12/2000 Updated: 03/05/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd openbsd 2.7

openbsd openbsd 2.3

openbsd openbsd 2.4

openbsd openbsd 2.5

openbsd openbsd 2.6

Exploits

source: wwwsecurityfocuscom/bid/1746/info fstat is a program shipped with BSD unix variants that is used to list the open files on a system It is installed sgid kmem so it can access information about open files from the kernel memory structures A user definable environment variable (PWD, parent working directory) is passed as the onl ...