PT-2000-1006 · Gnu · Glibc

Published

2000-09-30

·

Updated

2016-10-18

·

CVE-2000-1207

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions usermode versions 1.37 SysVinit version 2.78
Description The issue allows for the exploitation of format string vulnerabilities in glibc via the LANG or LC ALL environment variables. This can lead to a breach of confidentiality, integrity, and availability of protected information. The exploitation can be carried out locally.
Recommendations For usermode version 1.37, consider disabling the execution of non-setuid programs as root until a patch is available. For SysVinit version 2.78, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07830
BDU:2015-07833
CVE-2000-1207

Affected Products

Glibc