CVE
- Id
- 4135
- CVE No.
- CVE-2001-1331
- Status
- Candidate
- Description
- mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.
- Phase
- Proposed (20020502)
- Votes
- ACCEPT(3) Cole, Green, Wall | MODIFY(1) Frech | NOOP(2) Cox, Foat
- Comments
- CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:mandb-tmpfile-symlink(9989)