Lucene search

K
cve[email protected]CVE-2000-1207
HistoryJul 31, 2002 - 4:00 a.m.

CVE-2000-1207

2002-07-3104:00:00
web.nvd.nist.gov
29
cve-2000-1207
userhelper
red hat linux
root
glibc
format string vulnerability
cve-2000-0844
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.2 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

75.9%

userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).

Affected configurations

NVD
Node
redhatlinux
CPENameOperatorVersion
redhat:linuxredhat linuxeq*

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.2 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

75.9%

Related for CVE-2000-1207