CVE-2000-0844

CRITICAL ⚠ Exploit

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as ge...

Affects 16 products across 13 vendors.

BCS8.49
CVSS 2.010.0
EPSS15.3%
Percentile96th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-264: Permissions, Privileges, and Access Controls

Broad class covering failures in permission enforcement. Deprecated in favor of CWE-284, CWE-862, CWE-863.

◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability in the locale subsystem of Unix systems allows local attackers to execute arbitrary commands through improperly sanitized format strings in functions like gettext and catopen.

BSID: BS-2000-GLOBAL-157485-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2000-0844?
A vulnerability in the locale subsystem of Unix systems allows local attackers to execute arbitrary commands through improperly sanitized format strings in functions like gettext and catopen.
What is the CVSS score for CVE-2000-0844?
CVE-2000-0844 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 15.3%.
Is CVE-2000-0844 actively exploited?
Public exploit available for CVE-2000-0844. Exploitation risk elevated.
How do I remediate CVE-2000-0844?
Priority: IMMEDIATE. Advisory: http://archives.neohapsis.com/archives/bugtraq/2000-08/0457.html PSIRT: [email protected]
What systems are affected by CVE-2000-0844?
CVE-2000-0844 affects: Caldera, Caldera, Caldera, Conectiva, Debian, Ibm, Immunix, Mandrakesoft.
Vulnerability Details
CVE IDCVE-2000-0844
BSIDBS-2000-GLOBAL-157485-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2000-11-14
Last Modified2026-04-16
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The attack vector involves local attackers injecting malicious format strings into functions that handle locale data, leading to arbitrary code execution.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Caldera Openlinux
Caldera Openlinux Ebuilder
Caldera Openlinux Eserver
Conectiva Linux
Debian Debian Linux
Ibm Aix
Immunix Immunix
Mandrakesoft Mandrake Linux
Redhat Linux
Sgi Irix
Slackware Slackware Linux
Sun Sunos
Sun Solaris
Suse Suse Linux
Trustix Secure Linux
Turbolinux Turbolinux
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 9378 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Caldera
CVE-1999-0009 10.0 Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. CVE-1999-0002 10.0 Buffer overflow in NFS mountd gives root access to remote attackers, mostly i... CVE-1999-0047 10.0 MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4. CVE-1999-0042 10.0 Buffer overflow in University of Washington's implementation of IMAP and POP servers. CVE-2000-0370 10.0 The debug option in Caldera Linux smail allows remote attackers to execute co...
View all Caldera CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →