CVE-2003-0645: Medium severity Andries Brouwer Man vulnerability
Published Aug 14, 2003
·Updated
man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which could allow local users to gain privileges.
Affected Software
2 affected components
Andries Brouwer Man=2.3.20
Andries Brouwer Man=2.4.1
Remediation
Patch Available
Event History
Aug 14, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Aug 27, 2003
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0645?
CVE-2003-0645 is classified as a high severity vulnerability that allows local users to gain privileges.
2
How do I fix CVE-2003-0645?
To fix CVE-2003-0645, update the man-db package to versions later than 2.4.1.
3
What versions are affected by CVE-2003-0645?
CVE-2003-0645 affects man-db versions 2.3.12, 2.3.18, 2.3.20, and up to 2.4.1.
4
Who is affected by CVE-2003-0645?
Local users on systems running vulnerable versions of man-db are impacted by CVE-2003-0645.
5
What is the cause of CVE-2003-0645?
CVE-2003-0645 is caused by man-db processing user-controlled DEFINE directives from the ~/.manpath file when running setuid.