CVE-2000-0996
Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.
Date published : 2001-01-22
ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch