CVE-2000-1010Use of Externally-Controlled Format String in Openbsd

3 documents3 sources
Severity
10.0CRITICALNVD
EPSS
1.6%
top 18.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateApr 30

Description

Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDopenbsd/openbsd5 versions+4
NVDredhat/linux5.0, 5.1, 5.2+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pjfm-8j94-x5vc: Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user nam2022-04-30
CVEList
CVE-2000-1010: Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user nam2001-01-22
CVE-2000-1010 — Openbsd vulnerability | cvebase