PT-2003-1053 · Gnu · Man

Daniel Ahlberg

·

Publicado

2003-03-18

·

Atualizado

2017-10-10

·

CVE-2003-0124

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions man versions prior to 1.5l
Description The issue allows attackers to execute arbitrary code via a malformed man file with improper quotes. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of the issue can be carried out locally.
Recommendations For versions prior to 1.5l, update to version 1.5l or later to resolve the issue. As a temporary workaround, consider restricting access to malformed man files to minimize the risk of exploitation. Avoid using the my xsprintf function in the affected man package until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-07809
BDU:2015-07810
CVE-2003-0124

Produtos afetados

Man