Description
man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in the search path of the user who runs man.
Affected products
- andries_brouwer / man1.5h1 – 1.5h1
- andries_brouwer / man1.5i – 1.5i
- andries_brouwer / man1.5i2 – 1.5i2
- andries_brouwer / man1.5j – 1.5j
- andries_brouwer / man1.5k – 1.5k
References
- MAILING_LISThttp://marc.info/?l=bugtraq&m=104740927915154&w=2
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/11512
- MISChttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000620
- MISChttp://www.securityfocus.com/bid/7066
- MISChttp://www.redhat.com/support/errata/RHSA-2003-134.html
- MAILING_LISThttp://marc.info/?l=bugtraq&m=104802285112752&w=2
- MISChttp://www.redhat.com/support/errata/RHSA-2003-133.html