Back

CVE-2000-0947

Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.

Published: Dec 19, 2000 Modified: Apr 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
gnu cfengine 1.5
gnu cfengine 1.5.3-4
gnu cfengine 1.6

GitHub Security Advisory GHSA-32j9-px4f-v6vv

Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 0.92%

Top 24% most likely to be exploited

Threat Score 40.3 / 100

Data Sources

NVD EPSS GitHub