The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.
2017-09-28T01:29:00.420
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | man-db_project | man-db | ≤ 2.7.6.1 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | No |
Operating System | canonical | ubuntu_linux | 14.04 | No |
Operating System | canonical | ubuntu_linux | 16.04 | No |
Application | man-db_project | man-db | ≤ 2.7.6.1 | Yes |
Operating System | debian | debian_linux | 8.0 | No |
Operating System | debian | debian_linux | 9.0 | No |