4.6
CVSSv2

CVE-2003-0645

Published: 27/08/2003 Updated: 11/07/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which could allow local users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

andries brouwer man 2.3.20

andries brouwer man 2.4.1

Vendor Advisories

man-db provides the standard man(1) command on Debian systems During configuration of this package, the administrator is asked whether man(1) should run setuid to a dedicated user ("man") in order to provide a shared cache of preformatted manual pages The default is for man(1) NOT to be setuid, and in this configuration no known vulnerability exi ...

Exploits

#!/bin/bash # xmandbsh: shell command file # # man-db[v241-]: local uid=man exploit # by: vade79/v9 v9 fakehalo deadpig org (fakehalo) # # open_cat_stream() privileged call exploit # # i've been conversing with the new man-db maintainer, and after the # initial post sent to bugtraq(which i forgot to inform him), i sent him # an email highligh ...