makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Makewhatis | Wolfram_schneider | * | 1.5i2 (including) |