Vulnerabilities > CVE-2003-0620 - Unspecified vulnerability in Andries Brouwer MAN

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
andries-brouwer
nessus
exploit available

Summary

Multiple buffer overflows in man-db 2.4.1 and earlier, when installed setuid, allow local users to gain privileges via (1) MANDATORY_MANPATH, MANPATH_MAP, and MANDB_MAP arguments to add_to_dirlist in manp.c, (2) a long pathname to ult_src in ult_src.c, (3) a long .so argument to test_for_include in ult_src.c, (4) a long MANPATH environment variable, or (5) a long PATH environment variable.

Exploit-Db

descriptionManDB Utility 2.3/2.4 Local Buffer Overflow Vulnerabilities. CVE-2003-0620. Local exploit for linux platform
idEDB-ID:22971
last seen2016-02-02
modified2003-07-29
published2003-07-29
reporterV9
sourcehttps://www.exploit-db.com/download/22971/
titleManDB Utility 2.3/2.4 - Local Buffer Overflow Vulnerabilities

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-364.NASL
descriptionman-db provides the standard man(1) command on Debian systems. During configuration of this package, the administrator is asked whether man(1) should run setuid to a dedicated user (
last seen2020-06-01
modified2020-06-02
plugin id15201
published2004-09-29
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/15201
titleDebian DSA-364-3 : man-db - buffer overflows, arbitrary command execution