CVE-2003-0645
EPSS 0.74%
Description
man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which could allow local users to gain privileges.
How to fix CVE-2003-0645
To remediate CVE-2003-0645, upgrade the affected package to a fixed version below.
- Debian/man-db—upgrade to 2.4.1-13 or later
Is CVE-2003-0645 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.4.1-13