PT-2000-1006 · Gnu · Glibc
Publicado
2000-09-30
·
Atualizado
2016-10-18
·
CVE-2000-1207
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
usermode versions 1.37
SysVinit version 2.78
Description
The issue allows for the exploitation of format string vulnerabilities in glibc via the
LANG or LC ALL environment variables. This can lead to a breach of confidentiality, integrity, and availability of protected information. The exploitation can be carried out locally.Recommendations
For usermode version 1.37, consider disabling the execution of non-setuid programs as root until a patch is available.
For SysVinit version 2.78, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Glibc