Oval Definition:oval:org.cisecurity:def:1020
Revision Date:2016-09-16Version:6
Title:DSA-364-3 -- man-db -- buffer overflows, arbitrary command execution
Description:man-db provides the standard man(1) command on Debian systems. During configuration of this package, the administrator is asked whether man(1) should run setuid to a dedicated user ("man") in order to provide a shared cache of preformatted manual pages. The default is for man(1) NOT to be setuid, and in this configuration no known vulnerability exists. However, if the user explicitly requests setuid operation, a local attacker could exploit either of the following bugs to execute arbitrary code as the "man" user.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2003-0620
CVE-2003-0645
DSA-364-3
Platform(s):Debian GNU/Linux 3.0
Product(s):man-db
Definition Synopsis
  • Debian GNU/Linux 3.0 is installed
  • AND man-db is earlier than 0:2.3.20-18.woody.4
  • BACK