First published: Thu Jul 26 2001(Updated: )
Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
groff | =1.16.1 | |
groff | =1.11a | |
groff | =1.14 | |
GNU Groff | ||
groff | =1.10 | |
groff | =1.11 | |
groff | =1.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1022 is categorized as a medium severity vulnerability due to the potential for remote command execution.
To fix CVE-2001-1022, upgrade the groff utility to a version later than 1.16.1 or apply patches provided by your distribution.
CVE-2001-1022 affects groff versions 1.10 through 1.16.1 and jgroff versions before 1.15.
CVE-2001-1022 is a format string vulnerability that allows attackers to execute arbitrary commands.
Yes, CVE-2001-1022 can be exploited remotely, allowing attackers to bypass security mechanisms.