CVE Vulnerabilities

CVE-2001-1022

Published: Jul 26, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.

Affected Software

NameVendorStart VersionEnd Version
GroffGnu1.10 (including)1.10 (including)
GroffGnu1.11 (including)1.11 (including)
GroffGnu1.11a (including)1.11a (including)
GroffGnu1.14 (including)1.14 (including)
GroffGnu1.15 (including)1.15 (including)
GroffGnu1.16.1 (including)1.16.1 (including)
JgroffJgroff**
Red Hat Linux 7.0RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.2RedHat*

References