4.6

CVE-2003-0124

Exploit

man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in the search path of the user who runs man.

Data is provided by the National Vulnerability Database (NVD)
Andries BrouwerMan Version1.5h1
Andries BrouwerMan Version1.5i
Andries BrouwerMan Version1.5i2
Andries BrouwerMan Version1.5j
Andries BrouwerMan Version1.5k
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.89% 0.815
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P