CVE-2000-0917 describes a critical format string vulnerability in the use_syslog() function of LPRng 3.6.24, impacting distributions like Caldera, Red Hat, and Trustix. This vulnerability carries a CVSS score of 10.0 (HIGH), indicating it can be exploited remotely with low complexity and no authentication, leading to complete compromise of confidentiality, integrity, and availability. Exploit intelligence shows multiple public exploits, including Metasploit modules and several ExploitDB entries, confirming its exploitability. Despite the high severity and public exploits, there is no evidence of active exploitation, community discussion, or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:caldera:openlinux_ebuilder:3.0:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:caldera:openlinux:*:*:*:*:*:*:*:* | ||
2.4CPE matchmatch criteria | cpe:2.3:o:caldera:openlinux_edesktop:2.4:*:*:*:*:*:*:* | ||
2.3CPE matchmatch criteria | cpe:2.3:o:caldera:openlinux_eserver:2.3:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.