CNCVE编号:CNCVE-20000994 CVE编号:CVE-2000-0994 安全级别:高 漏洞中文描述: OpenBSD fstat 程序 (及可能其它基于BSD的操作系统) 中存在格式化字符串漏洞,这可导致本地用户通过PWD环境变量来获得root权限。 漏洞英文描述: Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable. 漏洞参考: BUGTRAQ:20001004 Re: OpenBSD Security Advisory | URL:http://www.securityfocus.com/archive/1/137482 | OPENBSD:20001006 There are printf-style format string bugs in several privileged programs. | MISC:ftp://ftp.openbsd.org/pub/OpenBSD/patches/2 系统类型:其他 漏洞类型:输入有效性检查错误