{"api_version":"1","generated_at":"2026-04-23T09:22:41+00:00","cve":"CVE-2000-1207","urls":{"html":"https://cve.report/CVE-2000-1207","api":"https://cve.report/api/cve/CVE-2000-1207.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2000-1207","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2000-1207"},"summary":{"title":"CVE-2000-1207","description":"userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).","state":"PUBLISHED","assigner":"mitre","published_at":"2000-09-30 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.redhat.com/support/errata/RHSA-2000-075.html","name":"http://www.redhat.com/support/errata/RHSA-2000-075.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=97063854808796&w=2","name":"http://marc.info/?l=bugtraq&m=97063854808796&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=97034397026473&w=2","name":"http://marc.info/?l=bugtraq&m=97034397026473&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'glibc and userhelper - local root' - MARC","mime":"text/x-c","httpstatus":"200","archivestatus":"200"},{"url":"http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-059.php3","name":"http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-059.php3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2000-1207","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2000-1207","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2000","cve_id":"1207","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"linux","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T05:45:37.389Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20001003 SuSE: userhelper/usermode","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=97063854808796&w=2"},{"name":"20000930 glibc and userhelper - local root","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=97034397026473&w=2"},{"name":"RHSA-2000:075","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2000-075.html"},{"name":"MDKSA-2000:059","tags":["vendor-advisory","x_refsource_MANDRAKE","x_transferred"],"url":"http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-059.php3"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2000-09-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844)."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20001003 SuSE: userhelper/usermode","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=97063854808796&w=2"},{"name":"20000930 glibc and userhelper - local root","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=97034397026473&w=2"},{"name":"RHSA-2000:075","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2000-075.html"},{"name":"MDKSA-2000:059","tags":["vendor-advisory","x_refsource_MANDRAKE"],"url":"http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-059.php3"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2000-1207","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20001003 SuSE: userhelper/usermode","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=97063854808796&w=2"},{"name":"20000930 glibc and userhelper - local root","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=97034397026473&w=2"},{"name":"RHSA-2000:075","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2000-075.html"},{"name":"MDKSA-2000:059","refsource":"MANDRAKE","url":"http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-059.php3"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2000-1207","datePublished":"2002-07-31T04:00:00.000Z","dateReserved":"2002-07-29T00:00:00.000Z","dateUpdated":"2024-08-08T05:45:37.389Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2000-09-30 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:linux:*:*:*:*:*:*:*:*","matchCriteriaId":"B133DAC8-2B0D-4F83-9025-AD071740187A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2000","CveId":"1207","Ordinal":"1","Title":"CVE-2000-1207","CVE":"CVE-2000-1207","Year":"2000"},"notes":[{"CveYear":"2000","CveId":"1207","Ordinal":"1","NoteData":"userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).","Type":"Description","Title":"CVE-2000-1207"},{"CveYear":"2000","CveId":"1207","Ordinal":"2","NoteData":"2002-07-31","Type":"Other","Title":"Published"},{"CveYear":"2000","CveId":"1207","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}