PT-2000-1859 · Gnu · Gnu Cfengine
Published
2000-12-19
·
Updated
2017-10-10
·
CVE-2000-0947
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GNU CFEngine versions prior to 1.6.0a11
Description
The issue is related to a format string vulnerability in the cfd daemon. This vulnerability allows attackers to execute arbitrary commands by including format characters in the CAUTH command.
Recommendations
For GNU CFEngine versions prior to 1.6.0a11, update to version 1.6.0a11 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gnu Cfengine