4.6

CVE-2003-0124

Exploit
man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in the search path of the user who runs man.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Andries BrouwerMan Version1.5h1
Andries BrouwerMan Version1.5i
Andries BrouwerMan Version1.5i2
Andries BrouwerMan Version1.5j
Andries BrouwerMan Version1.5k
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.51% 0.712
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000620
http://marc.info/?l=bugtraq&m=104740927915154&w=2
http://marc.info/?l=bugtraq&m=104802285112752&w=2
http://www.redhat.com/support/errata/RHSA-2003-133.html
http://www.redhat.com/support/errata/RHSA-2003-134.html
http://www.securityfocus.com/bid/7066
Patch
Vendor Advisory
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/11512