CNCVE编号:CNCVE-20000993 CVE编号:CVE-2000-0993 安全级别:高 漏洞中文描述: 在BSD libutil库中的pw_error函数中存在格式化字符串漏洞,导致本地用户可通过在诸如:chpass或passwd等命令中使用畸形的口令来获得root权限。 漏洞英文描述: Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd. 漏洞参考: OPENBSD:20001003 A format string vulnerability exists in the pw_error(3) function. | URL:http://www.openbsd.org/errata27.html#pw_error | NETBSD:NetBSD-SA2000-015 | URL:ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-015. 系统类型:其他 漏洞类型:输入有效性检查错误