mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Debian_linux | Debian | 2.2 (including) | 2.2 (including) |
Debian | Progeny | 1.0 (including) | 1.0 (including) |