LWN.net Logo

man-db: buffer overflow, command execution

Package(s):man-db CVE #(s):CAN-2003-0620 CAN-2003-0645
Created:August 5, 2003 Updated:August 18, 2003
Description: man-db 2.4.1 and earlier contains two separate vulnerabilities. There are several buffer overflows which could perhaps be locally exploited, and some directives in ~/.manpath are executed when they should not be. These vulnerabilities only matter if the package has been installed in the setuid mode.
Alerts:
Debian DSA-364-3 2003-08-18
Debian DSA-364-2 2003-08-08
Debian DSA-364-1 2003-08-04

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds