CVE-2001-0111

splitvt - Remote Code Execution via Format String in -rcfile Argument

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-0111. PoCs published by Michel Kaempf.

AI-analyzed exploit summary This exploit leverages a format string vulnerability in splitvt < 1.6.5 via the -rcfile command line flag. It crafts a malicious input to overwrite stack variables and execute arbitrary shellcode stored in the HOME environment variable, potentially leading to privilege escalation if splitvt is SUID root.

Description

Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Michel Kaempf · clocallinux
https://www.exploit-db.com/exploits/20556

This exploit leverages a format string vulnerability in splitvt < 1.6.5 via the -rcfile command line flag. It crafts a malicious input to overwrite stack variables and execute arbitrary shellcode stored in the HOME environment variable, potentially leading to privilege escalation if splitvt is SUID root.

Classification
Working Poc 95%
Attack Type
Rce | Lpe
Complexity
Complex
Reliability
Reliable
Target: splitvt < 1.6.5
No auth needed
Prerequisites: splitvt binary installed (preferably SUID root) · ability to set environment variables · ability to execute the binary with crafted arguments
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=97958269320974&w=2
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2210
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5948
Patch vendor-advisory x_refsource_debian
http://www.debian.org/security/2001/dsa-014

Scores

EPSS 0.0126
EPSS Percentile 65.9%

Details

Status published
Products (2)
debian/debian_linux 2.2 (6 CPE variants)
sam_lantinga/splitvt 1.6.4
Published Mar 12, 2001
Tracked Since Feb 18, 2026