CVE-2003-0124: Medium severity Andries Brouwer Man vulnerability
man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the myxsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in the search path of the user who runs man.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0124?
CVE-2003-0124 is considered to have a high severity due to the potential for arbitrary code execution.
How do I fix CVE-2003-0124?
To fix CVE-2003-0124, update the affected 'man' software to a version that contains the security patch.
What versions of Man are affected by CVE-2003-0124?
CVE-2003-0124 affects Man versions 1.5h1, 1.5i, 1.5k, 1.5i2, and 1.5j.
What are the consequences of exploiting CVE-2003-0124?
Exploiting CVE-2003-0124 allows an attacker to execute arbitrary code on the system, potentially compromising its security.
Is CVE-2003-0124 a local or remote vulnerability?
CVE-2003-0124 is a local vulnerability since it requires a user with the ability to run the 'man' command.