PT-2003-1053 · Gnu · Man

Daniel Ahlberg

·

Published

2003-03-18

·

Updated

2017-10-10

·

CVE-2003-0124

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions man versions prior to 1.5l
Description The issue allows attackers to execute arbitrary code via a malformed man file with improper quotes. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of the issue can be carried out locally.
Recommendations For versions prior to 1.5l, update to version 1.5l or later to resolve the issue. As a temporary workaround, consider restricting access to malformed man files to minimize the risk of exploitation. Avoid using the my xsprintf function in the affected man package until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07809
BDU:2015-07810
CVE-2003-0124

Affected Products

Man