CVE-2003-0620: Buffer Overflow

Published Aug 1, 2003
·
Updated

Multiple buffer overflows in man-db 2.4.1 and earlier, when installed setuid, allow local users to gain privileges via (1) MANDATORYMANPATH, MANPATHMAP, and MANDBMAP arguments to addtodirlist in manp.c, (2) a long pathname to ultsrc in ultsrc.c, (3) a long .so argument to testforinclude in ultsrc.c, (4) a long MANPATH environment variable, or (5) a long PATH environment variable.

Affected Software

5 affected components
Andries Brouwer Man=2.3.20
Andries Brouwer Man=2.4.1
Andries Brouwer Man=2.3.19
Andries Brouwer Man=2.3.18
Andries Brouwer Man=2.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Ensure man-db is not installed setuid. Remove the setuid bit from installed man binaries (for example: chmod u-s /usr/bin/man or equivalent for your system) so the man binary is not setuid.

    man-db setuid = disabled
  2. Operational

    Inventory systems for installations of man-db version 2.4.1 or earlier; for any found, immediately remove the setuid bit from the man binaries to mitigate the reported local privilege escalation vulnerabilities.

Event History

Aug 1, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Aug 27, 2003
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2003-0620?

CVE-2003-0620 has a high severity rating due to its potential to allow local users to escalate privileges.

2

How do I fix CVE-2003-0620?

To fix CVE-2003-0620, upgrade to a patched version of man-db that addresses the identified buffer overflow vulnerabilities.

3

Which versions of man-db are affected by CVE-2003-0620?

CVE-2003-0620 affects man-db versions 2.4.1 and earlier, including 2.3.18 to 2.3.20.

4

Who is the vendor associated with CVE-2003-0620?

The vendor associated with CVE-2003-0620 is Andries Brouwer, the maintainer of the man utility.

5

Is CVE-2003-0620 a remote or local vulnerability?

CVE-2003-0620 is a local vulnerability that can be exploited by users with access to the system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203