20010513 RH 7.0:/usr/bin/man exploit: gid man + moremailing list
http://archives.neohapsis.com/archives/bugtraq/2001-05/0087.html CVE-2001-0641
Immunix OS 6.2/7.0 / RedHat 5.2/6.2/7.0 / SuSE Linux 6.x/7.0/7.1 - 'Man -S' Heap Overflow
Record summary
CVE-2001-0641 has a selected CVSS score of 4.6; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group man via a long -S option.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBImmunix OS 6.2/7.0 / RedHat 5.2/6.2/7.0 / SuSE Linux 6.x/7.0/7.1 - 'Man -S' Heap OverflowExploitDB exploitby zenith parsecNot analyzed1 file
References
7SuSE-SA:2001:019Vendor advisory
http://www.novell.com/linux/security/advisories/2001_019_man_txt.html RHSA-2001:069Vendor advisory
http://www.redhat.com/support/errata/RHSA-2001-069.html 20010612 man 1.5h10 + man 1.5i-4 exploitsmailing list
http://www.securityfocus.com/archive/1/190136 2711vdb entry
http://www.securityfocus.com/bid/2711 man-s-bo(6530)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/6530 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0641