Format String Vulnerability in CFEngine Daemon by GNU
CVE-2000-0947

Currently unrated

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
19 December 2000

Summary

The CFEngine daemon prior to version 1.6.0a11 contains a format string vulnerability, which could be exploited by an attacker to execute arbitrary commands. The vulnerability arises from improper handling of format characters in the CAUTH command, allowing malicious inputs to be sent to the daemon. This can potentially lead to severe security implications, including unauthorized access to system resources.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.