CVE-2001-1022: High severity GNU groff vulnerability
Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1022?
CVE-2001-1022 is categorized as a medium severity vulnerability due to the potential for remote command execution.
How do I fix CVE-2001-1022?
To fix CVE-2001-1022, upgrade the groff utility to a version later than 1.16.1 or apply patches provided by your distribution.
What systems are affected by CVE-2001-1022?
CVE-2001-1022 affects groff versions 1.10 through 1.16.1 and jgroff versions before 1.15.
What type of vulnerability is CVE-2001-1022?
CVE-2001-1022 is a format string vulnerability that allows attackers to execute arbitrary commands.
Can CVE-2001-1022 be exploited remotely?
Yes, CVE-2001-1022 can be exploited remotely, allowing attackers to bypass security mechanisms.