Format String Vulnerability in CFEngine Daemon by GNU
CVE-2000-0947
Currently unrated
Summary
The CFEngine daemon prior to version 1.6.0a11 contains a format string vulnerability, which could be exploited by an attacker to execute arbitrary commands. The vulnerability arises from improper handling of format characters in the CAUTH command, allowing malicious inputs to be sent to the daemon. This can potentially lead to severe security implications, including unauthorized access to system resources.
References
Timeline
Vulnerability published
Vulnerability Reserved