CVE-2000-0666
published 2000-07-16CVE-2000-0666: rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain…
PriorityP351critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
26.32%
97.8th percentile
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| conectiva | linux | — | — |
| conectiva | linux | — | — |
| conectiva | linux | — | — |
| conectiva | linux | — | — |
| conectiva | linux | — | — |
| conectiva | linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| trustix | secure_linux | — | — |
| trustix | secure_linux | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jc43-58xv-97mp: rpc
ghsa_unreviewed·2022-04-30
CVE-2000-0666 [HIGH] GHSA-jc43-58xv-97mp: rpc
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.
Red Hat
security flaw
vendor_redhat·2000-07-16·CVSS 10.0
CVE-2000-0666 [CRITICAL] security flaw
security flaw
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.
Statement: This issue was fixed in the following products:
- Red Hat Linux 6.0 - RHSA-2000:043 (2000-07-17)
- Red Hat Linux 6.1 - RHSA-2000:043 (2000-07-17)
- Red Hat Linux 6.2 - RHSA-2000:043 (2000-07-17)
Red Hat
CVE-2000-0800: String parsing error in rpc
vendor_redhat·CVSS 10.0
CVE-2000-0800 [CRITICAL] CVE-2000-0800: String parsing error in rpc
String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.
Statement: This issue is a duplicate of CVE-2000-0666, which has been corrected via RHSA-2000:043.
Suricata
GPL RPC STATD UDP monitor mon_name format string exploit attempt
suricata·2010-09-23
CVE-2000-0666 GPL RPC STATD UDP monitor mon_name format string exploit attempt
GPL RPC STATD UDP monitor mon_name format string exploit attempt
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET any (msg:"GPL RPC STATD UDP monitor mon_name format string exploit attempt"; content:"|00 01 86 B8|"; depth:4; offset:12; content:"|00 00 00 02|"; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,>,100,0,relative; content:"|00 00 00 00|"; depth:4; offset:4; reference:bugtraq,1480; reference:cve,2000-0666; classtype:attempted-admin; sid:2101915; rev:10; metadata:created_at 2010_09_23, cve CVE_2000_0666, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
Suricata
GPL RPC STATD TCP monitor mon_name format string exploit attempt
suricata·2010-09-23
CVE-2000-0666 GPL RPC STATD TCP monitor mon_name format string exploit attempt
GPL RPC STATD TCP monitor mon_name format string exploit attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"GPL RPC STATD TCP monitor mon_name format string exploit attempt"; flow:established,to_server; content:"|00 01 86 B8|"; depth:4; offset:16; content:"|00 00 00 02|"; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,>,100,0,relative; content:"|00 00 00 00|"; depth:4; offset:8; reference:bugtraq,1480; reference:cve,2000-0666; classtype:attempted-admin; sid:2101916; rev:11; metadata:created_at 2010_09_23, cve CVE_2000_0666, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
GPL RPC STATD UDP stat mon_name format string exploit attempt
suricata·2010-09-23
CVE-2000-0666 GPL RPC STATD UDP stat mon_name format string exploit attempt
GPL RPC STATD UDP stat mon_name format string exploit attempt
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET any (msg:"GPL RPC STATD UDP stat mon_name format string exploit attempt"; content:"|00 01 86 B8|"; depth:4; offset:12; content:"|00 00 00 01|"; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,>,100,0,relative; content:"|00 00 00 00|"; depth:4; offset:4; reference:bugtraq,1480; reference:cve,2000-0666; classtype:attempted-admin; sid:2101913; rev:11; metadata:created_at 2010_09_23, cve CVE_2000_0666, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
Suricata
GPL RPC STATD TCP stat mon_name format string exploit attempt
suricata·2010-09-23
CVE-2000-0666 GPL RPC STATD TCP stat mon_name format string exploit attempt
GPL RPC STATD TCP stat mon_name format string exploit attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"GPL RPC STATD TCP stat mon_name format string exploit attempt"; flow:established,to_server; content:"|00 01 86 B8|"; depth:4; offset:16; content:"|00 00 00 01|"; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,>,100,0,relative; content:"|00 00 00 00|"; depth:4; offset:8; reference:bugtraq,1480; reference:cve,2000-0666; classtype:attempted-admin; sid:2101914; rev:12; metadata:created_at 2010_09_23, cve CVE_2000_0666, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Exploit-DB
Conectiva 4.x/5.x / Debian 2.x / RedHat 6.x / S.u.S.E 6.x/7.0 / Trustix 1.x - rpc.statd Remote Format String (3)
exploitdb·2000-08-03
CVE-2000-0666 Conectiva 4.x/5.x / Debian 2.x / RedHat 6.x / S.u.S.E 6.x/7.0 / Trustix 1.x - rpc.statd Remote Format String (3)
Conectiva 4.x/5.x / Debian 2.x / RedHat 6.x / S.u.S.E 6.x/7.0 / Trustix 1.x - rpc.statd Remote Format String (3)
---
// source: https://www.securityfocus.com/bid/1480/info
A vulnerability exists in the 'rpc.statd' program, which is part of the 'nfs-utils' package that is shipped with a number of popular Linux distributions. Because of a format-string vulnerability when calling the 'syslog()' function, a remote attacker can execute code as root.
The 'rpc.statd' server is an RPC server that implements the Network Status and Monitor RPC protocol. It's a component of the Network File System (NFS) architecture.
The logging code in 'rpc.statd' uses the 'syslog()' function, passing it as the format string user-supplied data. A malicious user can construct a format string that injects executa
Exploit-DB
Conectiva 4.x/5.x / Debian 2.x / RedHat 6.x / S.u.S.E 6.x/7.0 / Trustix 1.x - rpc.statd Remote Format String (2)
exploitdb·2000-08-01
CVE-2000-0666 Conectiva 4.x/5.x / Debian 2.x / RedHat 6.x / S.u.S.E 6.x/7.0 / Trustix 1.x - rpc.statd Remote Format String (2)
Conectiva 4.x/5.x / Debian 2.x / RedHat 6.x / S.u.S.E 6.x/7.0 / Trustix 1.x - rpc.statd Remote Format String (2)
---
// source: https://www.securityfocus.com/bid/1480/info
A vulnerability exists in the 'rpc.statd' program, which is part of the 'nfs-utils' package that is shipped with a number of popular Linux distributions. Because of a format-string vulnerability when calling the 'syslog()' function, a remote attacker can execute code as root.
The 'rpc.statd' server is an RPC server that implements the Network Status and Monitor RPC protocol. It's a component of the Network File System (NFS) architecture.
The logging code in 'rpc.statd' uses the 'syslog()' function, passing it as the format string user-supplied data. A malicious user can construct a format string that injects executa
Exploit-DB
Conectiva 4.x/5.x / Debian 2.x / RedHat 6.x / S.u.S.E 6.x/7.0 / Trustix 1.x - rpc.statd Remote Format String (1)
exploitdb·2000-07-16
CVE-2000-0666 Conectiva 4.x/5.x / Debian 2.x / RedHat 6.x / S.u.S.E 6.x/7.0 / Trustix 1.x - rpc.statd Remote Format String (1)
Conectiva 4.x/5.x / Debian 2.x / RedHat 6.x / S.u.S.E 6.x/7.0 / Trustix 1.x - rpc.statd Remote Format String (1)
---
// source: https://www.securityfocus.com/bid/1480/info
A vulnerability exists in the 'rpc.statd' program, which is part of the 'nfs-utils' package that is shipped with a number of popular Linux distributions. Because of a format-string vulnerability when calling the 'syslog()' function, a remote attacker can execute code as root.
The 'rpc.statd' server is an RPC server that implements the Network Status and Monitor RPC protocol. It's a component of the Network File System (NFS) architecture.
The logging code in 'rpc.statd' uses the 'syslog()' function, passing it as the format string user-supplied data. A malicious user can construct a format string that injects executa
http://archives.neohapsis.com/archives/bugtraq/2000-07/0206.htmlhttp://archives.neohapsis.com/archives/bugtraq/2000-07/0230.htmlhttp://archives.neohapsis.com/archives/bugtraq/2000-07/0236.htmlhttp://archives.neohapsis.com/archives/bugtraq/2000-07/0260.htmlhttp://www.calderasystems.com/support/security/advisories/CSSA-2000-025.0.txthttp://www.cert.org/advisories/CA-2000-17.htmlhttp://www.redhat.com/support/errata/RHSA-2000-043.htmlhttp://www.securityfocus.com/bid/1480https://exchange.xforce.ibmcloud.com/vulnerabilities/4939http://archives.neohapsis.com/archives/bugtraq/2000-07/0206.htmlhttp://archives.neohapsis.com/archives/bugtraq/2000-07/0230.htmlhttp://archives.neohapsis.com/archives/bugtraq/2000-07/0236.htmlhttp://archives.neohapsis.com/archives/bugtraq/2000-07/0260.htmlhttp://www.calderasystems.com/support/security/advisories/CSSA-2000-025.0.txthttp://www.cert.org/advisories/CA-2000-17.htmlhttp://www.redhat.com/support/errata/RHSA-2000-043.htmlhttp://www.securityfocus.com/bid/1480https://exchange.xforce.ibmcloud.com/vulnerabilities/4939
2000-07-16
Published