First published: Tue Jul 17 2001(Updated: )
docview before 1.0-15 allows remote attackers to execute arbitrary commands via shell metacharacters that are processed when converting a man page to a web page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SCO OpenLinux Server | =3.1 | |
SCO OpenLinux Workstation | =3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0980 is considered a critical vulnerability as it allows remote attackers to execute arbitrary commands.
To fix CVE-2001-0980, update to docview version 1.0-15 or later to eliminate the risk of command injection.
CVE-2001-0980 affects SCO OpenLinux Server and Workstation version 3.1.
Yes, CVE-2001-0980 can be exploited remotely through crafted man pages.
CVE-2001-0980 facilitates command injection attacks via improper handling of shell metacharacters.