The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.
2017-09-28T01:29:00.420
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | man-db_project | man-db | ≤ 2.7.6.1 | Yes |
| Operating System | canonical | ubuntu_linux | 12.04 | No |
| Operating System | canonical | ubuntu_linux | 14.04 | No |
| Operating System | canonical | ubuntu_linux | 16.04 | No |
| Application | man-db_project | man-db | ≤ 2.7.6.1 | Yes |
| Operating System | debian | debian_linux | 8.0 | No |
| Operating System | debian | debian_linux | 9.0 | No |