CVE-2000-0844

Caldera Openlinux Ebuilder - Access Control

Title source: rule
STIX 2.1

Description

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.

Exploits (11)

exploitdb WORKING POC VERIFIED
by logikal · clocallinux
https://www.exploit-db.com/exploits/249
exploitdb WORKING POC VERIFIED
by sk8 · clocallinux
https://www.exploit-db.com/exploits/215
exploitdb WORKING POC VERIFIED
by warning3 · clocalsolaris
https://www.exploit-db.com/exploits/210
exploitdb WORKING POC VERIFIED
by localcore · clocallinux
https://www.exploit-db.com/exploits/209
exploitdb WORKING POC VERIFIED
by Solar Eclipse · clocalsolaris
https://www.exploit-db.com/exploits/197
exploitdb WORKING POC VERIFIED
by warning3 · clocalsolaris
https://www.exploit-db.com/exploits/20186
exploitdb WORKING POC VERIFIED
by warning3 · clocalsolaris
https://www.exploit-db.com/exploits/20188
exploitdb WORKING POC VERIFIED
by warning3 · clocallinux
https://www.exploit-db.com/exploits/20185
exploitdb WORKING POC VERIFIED
by anonymous · clocalunix
https://www.exploit-db.com/exploits/20190
exploitdb WORKING POC VERIFIED
by Synnergy.net · clocalunix
https://www.exploit-db.com/exploits/20189
exploitdb WORKING POC VERIFIED
by Kil3r of Lam3rZ · clocalimmunix
https://www.exploit-db.com/exploits/20187

Scores

EPSS 0.0089
EPSS Percentile 75.6%

Details

CWE
CWE-264
Status published
Products (50)
caldera/openlinux
caldera/openlinux_ebuilder 3.0
caldera/openlinux_eserver 2.3
conectiva/linux 4.0
conectiva/linux 4.0es
conectiva/linux 4.1
conectiva/linux 4.2
conectiva/linux 5.0
conectiva/linux 5.1
debian/debian_linux 2.0
... and 40 more
Published Nov 14, 2000
Tracked Since Feb 18, 2026