CVE-2001-1022

groff - Remote Code Execution via Format String in pic Utility

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-1022. PoCs published by zen-parse.

AI-analyzed exploit summary This exploit targets a format string vulnerability in the 'pic' utility (part of groff) via lpd, allowing remote command execution. It crafts a malicious print job to trigger arbitrary command execution on vulnerable systems.

Description

Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.

Exploits (1)

exploitdb WORKING POC VERIFIED
by zen-parse · cremotelinux
https://www.exploit-db.com/exploits/21037

This exploit targets a format string vulnerability in the 'pic' utility (part of groff) via lpd, allowing remote command execution. It crafts a malicious print job to trigger arbitrary command execution on vulnerable systems.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: groff (pic utility) in Red Hat Linux 7.0 (groff-1.16-7)
No auth needed
Prerequisites: Network access to lpd (port 515) · Vulnerable version of groff/pic · Netcat (nc) installed on attacker's machine
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000428
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2002/dsa-107
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6918
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3103
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2001/dsa-072
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/1914
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2002-004.html
Patch mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/199706

Scores

EPSS 0.1144
EPSS Percentile 95.5%

Details

Status published
Products (7)
gnu/groff 1.10
gnu/groff 1.11
gnu/groff 1.11a
gnu/groff 1.14
gnu/groff 1.15
gnu/groff 1.16.1
jgroff/jgroff
Published Jul 26, 2001
Tracked Since Feb 18, 2026