makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Makewhatis |
Wolfram_schneider |
* |
1.5i2 (including) |
References