man-db before 2.8.5 on Gentoo allows local users (with access to the man user account) to gain root privileges because /usr/bin/mandb is executed by root but not owned by root. (Also, the owner can strip the setuid and setgid bits.)
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-25078.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "2.8.5" } ] } ]