ManDB Utility Local Buffer Overflow Vulnerability
BID:8278
Info
ManDB Utility Local Buffer Overflow Vulnerability
| Bugtraq ID: | 8278 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 25 2003 12:00AM |
| Updated: | Jul 25 2003 12:00AM |
| Credit: | This vulnerability has been disclosed in a Conectiva announcement. |
| Vulnerable: |
man man 2.3.19 |
| Not Vulnerable: | |
Discussion
ManDB Utility Local Buffer Overflow Vulnerability
mandb utility has been reported prone to a local buffer overflow vulnerability.
It has been reported that a local attacker may exploit this issue to execute arbitrary instructions with elevated privileges. Specifically, user 'man' privileges.
mandb utility has been reported prone to a local buffer overflow vulnerability.
It has been reported that a local attacker may exploit this issue to execute arbitrary instructions with elevated privileges. Specifically, user 'man' privileges.
Exploit / POC
ManDB Utility Local Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ManDB Utility Local Buffer Overflow Vulnerability
Solution:
Conectiva has released an announcement (CLSA-2003:707) and patches to address this issue. Affected customers are advised to upgrade as soon as possible. See referenced announcement for further detail on obtaining and applying fixes.
man man 2.3.19
Solution:
Conectiva has released an announcement (CLSA-2003:707) and patches to address this issue. Affected customers are advised to upgrade as soon as possible. See referenced announcement for further detail on obtaining and applying fixes.
man man 2.3.19
-
Conectiva man-2.3.19deb4.0-617.i586.rpm
ftp://ul.conectiva.com.br/updates/1.0/RPMS.core/man-2.3.19deb4.0-617.i 586.rpm -
Conectiva man-2.3.19deb4.0-617.src.rpm
ftp://ul.conectiva.com.br/updates/1.0/SRPMS.core/man-2.3.19deb4.0-617. src.rpm