vendor:
man-db
by:
vade79/v9 (fakehalo)
7.5
CVSS
HIGH
Local Privilege Escalation
Not mentioned
CWE
Product Name: man-db
Affected Version From: 2.4.1 and below
Affected Version To: 2.4.2001
Patch Exists: NO
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: Red Hat 7.1
Not mentioned
man-db Local Privilege Escalation
This exploit takes advantage of a vulnerability in the man-db package. By exploiting the open_cat_stream() function, an attacker can escalate their privileges and gain root access on the system. The exploit involves creating fake manpage directories and files, compiling a source file, and executing man-db/man.
Mitigation:
Upgrade to a patched version of man-db or apply the necessary security patches. Ensure that the man-db package is always up to date.