CVE-2001-1277 Information

Description

makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.

Reference

http://marc.info/?l=bugtraq&m=99227597227747&w=2 http://www.redhat.com/support/errata/RHSA-2001-072.html https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=41805

Share on: