Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Man-db DEFINE Arbitrary Command Execution Vulnerability

man-db can allow a local user to execute commands with elevated privileges through the DEFINE directive. This would only occur if man-db were installed to run as setuid "man" which is not the default.







 

Privacy Statement
Copyright 2008, SecurityFocus