Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
Loading...
Loading...
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
November 14, 2000
April 16, 2026
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (10 Exploit-DB entries). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
GLIBC locale - Format Strings
Open source ↗GLIBC locale - bug mount
Open source ↗GLIBC - '/bin/su' Local Privilege Escalation
Open source ↗Solaris 2.6/7.0 - 'locale' Format Strings noexec stack Overflow
Open source ↗Solaris/SPARC 2.7 / 7 locale - Format String
Open source ↗Solaris 2.6/7.0 /locale - Subsystem Format String
Open source ↗Solaris 2.6/7.0 'eject' locale - Subsystem Format String
Open source ↗RedHat 6 GLIBC/locale - Subsystem Format String
Open source ↗Immunix OS 6.2 - LC glibc format string
Open source ↗Libc locale - Local Privilege Escalation (1)
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2000-0844
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.