BSD Today: OpenBSD Security Advisory - Format string vulnerability in libutil pw_error(3) function | Linux Today

BSD Today: OpenBSD Security Advisory – Format string vulnerability in libutil pw_error(3) function

Written By
Web Webster
Web Webster
Oct 4, 2000

“A format string vulnerability present in the pw_error()
function of OpenBSD 2.7’s libutil library can yield localhost users
root access through the setuid /usr/bin/chpass utility. This
particular vulnerability was repaired three months ago on June 30th
in OpenBSD-current during a complete source tree audit for format
string problems.”

“OpenBSD developers became aware of an exploit circulating for
the chpass(1) program on the evening of October 2, 2000….”

“In recent months a myriad of “format string” vulnerabilities
have been discovered in a number of software packages. In response
to this threat, the OpenBSD team immediately began a complete
source tree audit, identifying and fixing dozens of these format
bugs. While most of the issues were harmless, a few such as the bug
in xlock and one in the OpenBSD ftpd daemon raised the red flag and
patches were released to correct these problems. Unfortunately,
the severity of the format string bug that was fixed in pw_error()
was not fully realized at the time.

Complete
Security Advisory

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.