Record summary

CVE-2000-0844 has a selected CVSS score of 10.0; EIP currently links 11 catalogued exploits.

Description

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
11

Proofs of concept

11

Catalogued exploits

ExploitDBSolaris/SPARC 2.7 / 7 locale - Format StringExploitDB exploitby Solar EclipseNot analyzed1 file
ExploitDB

PoC details
ExploitDBRedHat 6 GLIBC/locale - Subsystem Format StringExploitDB exploitby warning3Not analyzed1 file
ExploitDB

PoC details
ExploitDBSolaris 2.6/7.0 /locale - Subsystem Format StringExploitDB exploitby warning3Not analyzed1 file
ExploitDB

PoC details
ExploitDBImmunix OS 6.2 - LC glibc format stringExploitDB exploitby Kil3r of Lam3rZNot analyzed1 file
ExploitDB

PoC details
ExploitDBSolaris 2.6/7.0 'eject' locale - Subsystem Format StringExploitDB exploitby warning3Not analyzed1 file
ExploitDB

PoC details
ExploitDBLibc locale - Local Privilege Escalation (1)ExploitDB exploitby Synnergy.netNot analyzed1 file
ExploitDB

PoC details
ExploitDBLibc locale - Local Privilege Escalation (2)ExploitDB exploitby anonymousNot analyzed1 file
ExploitDB

PoC details
ExploitDBGLIBC - '/bin/su' Local Privilege EscalationExploitDB exploitby localcoreNot analyzed1 file
ExploitDB

PoC details
ExploitDBSolaris 2.6/7.0 - 'locale' Format Strings noexec stack OverflowExploitDB exploitby warning3Not analyzed1 file
ExploitDB

PoC details
ExploitDBGLIBC locale - bug mountExploitDB exploitby sk8Not analyzed1 file
ExploitDB

PoC details
ExploitDBGLIBC locale - Format StringsExploitDB exploitby logikalNot analyzed1 file
ExploitDB

PoC details

References

12