CVE-2000-1013

Executive Summary

CVE-2000-1013 exposes a flaw in FreeBSD 5.0 and earlier where the setlocale function processes the LANG environment variable, enabling local users to read arbitrary files. This local file disclosure can lead to sensitive data exposure and potential privilege escalation within the affected system. The vulnerability is not currently listed in the CISA KEV database.


Authoritative CVE Metadata - CVSS Base Score: 7.2 (HIGH) - Published: 2000-12-11T05:00:00.000 - Last Modified: 2026-09-23T14:10:00.190

Original Description: The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.

"He that is giddy thinks the world turns round."

— William Shakespeare
Source: NVD