makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.
Link | Tags |
---|---|
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=41805 | |
http://marc.info/?l=bugtraq&m=99227597227747&w=2 | mailing list |
http://www.redhat.com/support/errata/RHSA-2001-072.html | patch vendor advisory |