Back

CVE-2000-0996

Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.

Published: Dec 19, 2000 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
openbsd openbsd *

GitHub Security Advisory GHSA-fq86-7hfr-cx3q

Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 0.54%

Top 58% most likely to be exploited

Threat Score 29 / 100

Data Sources

NVD EPSS GitHub