vendor:
Man System Manual Pager Program
by:
jenggo
7,2
CVSS
HIGH
Symlink Redirection
59
CWE
Product Name: Man System Manual Pager Program
Affected Version From: man-1.5h1-20
Affected Version To: man-1.5h1-20
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Redhat7.1
2001
Man System Manual Pager Program Vulnerability
It is possible for local users to cause man to cache files in the system cache directory from outside of the configured manual page hierarchy search path. Combined with the behaviours of 'man' and 'mandb' or any other utilities which trust cache filenames, it may be possible to use this vulnerability to elevate privileges.
Mitigation:
Ensure that the system cache directory is not writable by non-privileged users.