vendor:
man Command
by:
5.5
CVSS
MEDIUM
Arbitrary File Creation
377
CWE
Product Name: man Command
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:man:man
Platforms Tested: Linux, Unix
Arbitrary File Creation Vulnerability in man Command
The man command creates a temporary file under /tmp with a predictable name and is willing to follow symbolic links. This allows malicious local users to create arbitrarily named files by creating symbolic links to desired files.
Mitigation:
Upgrade to a version of man that does not have this vulnerability. Avoid running the man command as a privileged user.