Vulnerability Name: | CVE-2003-0124 (CCN-11512) | ||||||||
Assigned: | 2003-03-11 | ||||||||
Published: | 2003-03-11 | ||||||||
Updated: | 2017-10-10 | ||||||||
Summary: | man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in the search path of the user who runs man. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Mar 11 2003 - 12:24:01 CST Vulnerability in man < 1.5l Source: MITRE Type: CNA CVE-2003-0124 Source: CONECTIVA Type: UNKNOWN CLSA-2003:620 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2003:620 man Source: BUGTRAQ Type: UNKNOWN 20030311 Vulnerability in man < 1.5l Source: GENTOO Type: UNKNOWN GLSA-200303-13 Source: CCN Type: RHSA-2003-133 Updated man packages fix minor vulnerability Source: CCN Type: RHSA-2003-134 man security update Source: CCN Type: Gentoo Linux Security Announcement 200303-13 man arbitrary code execution Source: REDHAT Type: UNKNOWN RHSA-2003:133 Source: REDHAT Type: UNKNOWN RHSA-2003:134 Source: BID Type: Exploit, Patch, Vendor Advisory 7066 Source: CCN Type: BID-7066 Man Program Unsafe Return Value Command Execution Vulnerability Source: CCN Type: TLSA-2003-20 Vulnerability in man Source: XF Type: UNKNOWN man-myxsprintf-code-execution(11512) Source: XF Type: UNKNOWN man-myxsprintf-code-execution(11512) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |