CVE-2001-1022

Groff <1.16.1/jgroff <1.15 - RCE

Title source: llm
STIX 2.1

Description

Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.

Exploits (1)

exploitdb WORKING POC VERIFIED
by zen-parse · cremotelinux
https://www.exploit-db.com/exploits/21037

Scores

EPSS 0.2122
EPSS Percentile 95.7%

Details

Status published
Products (7)
gnu/groff 1.10
gnu/groff 1.11
gnu/groff 1.11a
gnu/groff 1.14
gnu/groff 1.15
gnu/groff 1.16.1
jgroff/jgroff
Published Jul 26, 2001
Tracked Since Feb 18, 2026