Back

CVE-2000-0993

Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.

Published: Dec 19, 2000 Modified: Apr 16, 2026

CVSS Metrics

Affected Products (13)

Vendor Product Version
freebsd freebsd 3.2
freebsd freebsd 3.3
freebsd freebsd 3.4
freebsd freebsd 3.5
freebsd freebsd 4.0
netbsd netbsd 1.4
netbsd netbsd 1.4.1
netbsd netbsd 1.4.2
openbsd openbsd 2.3
openbsd openbsd 2.4
openbsd openbsd 2.5
openbsd openbsd 2.6
openbsd openbsd 2.7

GitHub Security Advisory GHSA-qw7m-3wrp-h96f

Format string vulnerability in pw_error function in BSD libutil library allows local users to...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 0.23%

Top 54% most likely to be exploited

Threat Score 28.9 / 100

Data Sources

NVD EPSS GitHub