Man-db DEFINE Arbitrary Command Execution Vulnerability
BID:8341
Info
Man-db DEFINE Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 8341 |
| Class: | Design Error |
| CVE: |
CVE-2003-0645 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 04 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Announced in a Debian advisory. |
| Vulnerable: |
man man 2.4.1 man man 2.3.20 |
| Not Vulnerable: | |
Discussion
Man-db DEFINE Arbitrary Command Execution Vulnerability
man-db can allow a local user to execute commands with elevated privileges through the DEFINE directive. This would only occur if man-db were installed to run as setuid "man" which is not the default.
man-db can allow a local user to execute commands with elevated privileges through the DEFINE directive. This would only occur if man-db were installed to run as setuid "man" which is not the default.
Exploit / POC
Man-db DEFINE Arbitrary Command Execution Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Man-db DEFINE Arbitrary Command Execution Vulnerability
Solution:
Debian has released advisory DSA 364-1 with fixes for this issue. See the
referenced advisory for links to fixed packages.
Solution:
Debian has released advisory DSA 364-1 with fixes for this issue. See the
referenced advisory for links to fixed packages.