Man Utility Local Compression Program Privilege Elevation Vulnerability
BID:8675
Info
Man Utility Local Compression Program Privilege Elevation Vulnerability
| Bugtraq ID: | 8675 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 22 2003 12:00AM |
| Updated: | Sep 22 2003 12:00AM |
| Credit: | This vulnerability was reported in a Conectiva advisory. |
| Vulnerable: |
man man 2.3.19 |
| Not Vulnerable: | |
Discussion
Man Utility Local Compression Program Privilege Elevation Vulnerability
A vulnerability has been reported in man that may allow an attacker to gain elevated privileges. The problem lies in man failing to carry out sufficient sanity checks before executing a user-defined compression program. As a result, it may be possible for an attacker to execute arbitrary code with user 'man' privileges.
A vulnerability has been reported in man that may allow an attacker to gain elevated privileges. The problem lies in man failing to carry out sufficient sanity checks before executing a user-defined compression program. As a result, it may be possible for an attacker to execute arbitrary code with user 'man' privileges.
Exploit / POC
Man Utility Local Compression Program Privilege Elevation Vulnerability
No exploit required. The following proof of concept has been supplied:
No exploit required. The following proof of concept has been supplied: