PT-2023-10819 · Man Db+1 · Man-Db+1

Michael Orlitzky

·

Published

2019-07-01

·

Updated

2023-10-08

·

CVE-2018-25078

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions man-db versions prior to 2.8.5
Description The issue allows local users with access to the man user account to gain root privileges because /usr/bin/mandb is executed by root but not owned by root. Additionally, the owner can strip the setuid and setgid bits.
Recommendations For versions prior to 2.8.5, update to version 2.8.5 or later to resolve the issue. As a temporary workaround, consider changing the ownership of /usr/bin/mandb to root to prevent exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2192
ALT-PU-2019-3123
CVE-2018-25078

Affected Products

Alt Linux
Man-Db