20001004 Re: OpenBSD Security Advisorymailing list
http://marc.info/?l=bugtraq&m=97068555106135&w=2 CVE-2000-0994
OpenBSD 2.x - 'fstat' Format String
Record summary
CVE-2000-0994 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOpenBSD 2.x - 'fstat' Format StringExploitDB exploitby K2Not analyzed1 file
References
41746vdb entry
http://www.securityfocus.com/bid/1746 bsd-fstat-format(5338)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5338 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0994