Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Groff | Gnu | 1.10 (including) | 1.10 (including) |
Groff | Gnu | 1.11 (including) | 1.11 (including) |
Groff | Gnu | 1.11a (including) | 1.11a (including) |
Groff | Gnu | 1.14 (including) | 1.14 (including) |
Groff | Gnu | 1.15 (including) | 1.15 (including) |
Groff | Gnu | 1.16.1 (including) | 1.16.1 (including) |
Jgroff | Jgroff | * | * |
Red Hat Linux 7.0 | RedHat | * | |
Red Hat Linux 7.1 | RedHat | * | |
Red Hat Linux 7.2 | RedHat | * |