CVE-2000-0733

IRIX 5.2-6.1 - Remote Code Execution via Telnetd Format String Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0733. PoCs published by Last Stage of Delirium.

AI-analyzed exploit summary This exploit targets a format string vulnerability in the IRIX telnet daemon (CVE-2000-0733), allowing remote code execution as root by manipulating environment variables via the IAB-SB-TELOPT_ENVIRON request. It includes shellcode and carefully crafted payloads to overwrite stack values.

Description

Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Last Stage of Delirium · cremoteirix
https://www.exploit-db.com/exploits/20149

This exploit targets a format string vulnerability in the IRIX telnet daemon (CVE-2000-0733), allowing remote code execution as root by manipulating environment variables via the IAB-SB-TELOPT_ENVIRON request. It includes shellcode and carefully crafted payloads to overwrite stack values.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: SGI IRIX telnetd (versions 6.2 through 6.5.8)
No auth needed
Prerequisites: Network access to the target's telnet service (port 23) · Vulnerable IRIX version without the 1010 or 1020 series patches
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-08/0154.html
Various Sources vendor-advisory x_refsource_sgi
ftp://sgigate.sgi.com/security/20000801-02-P
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1572

Scores

EPSS 0.1240
EPSS Percentile 95.7%

Details

Status published
Products (18)
sgi/irix 5.2
sgi/irix 5.3 (2 CPE variants)
sgi/irix 6.0
sgi/irix 6.0.1 (2 CPE variants)
sgi/irix 6.1
sgi/irix 6.2
sgi/irix 6.3
sgi/irix 6.4
sgi/irix 6.5
sgi/irix 6.5.1
... and 8 more
Published Oct 20, 2000
Tracked Since Feb 18, 2026