First published: Thu May 03 2001(Updated: )
mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Linux | =2.2 | |
Debian | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1331 is considered a high severity vulnerability due to its potential for local users to overwrite arbitrary files.
To fix CVE-2001-1331, upgrade the man-db package to version 2.3.16-3 or later.
CVE-2001-1331 affects local users on systems running the man-db package before version 2.3.16-3.
Vulnerable systems include Debian GNU/Linux 2.2 and Progeny Debian 1.0.
The commands -u and -c in mandb are misconfigured in CVE-2001-1331, allowing file overwriting without dropping privileges.