CVE-2003-0645

Source
https://nvd.nist.gov/vuln/detail/CVE-2003-0645
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2003-0645.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2003-0645
Related
Published
2003-08-27T04:00:00Z
Modified
2024-11-20T23:45:13Z
Summary
[none]
Details

man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which could allow local users to gain privileges.

References

Affected packages

Debian:11 / man-db

Package

Name
man-db
Purl
pkg:deb/debian/man-db?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.1-13

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / man-db

Package

Name
man-db
Purl
pkg:deb/debian/man-db?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.1-13

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / man-db

Package

Name
man-db
Purl
pkg:deb/debian/man-db?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.1-13

Ecosystem specific

{
    "urgency": "not yet assigned"
}