CVE-2001-1022
Published Jul 26, 2001
Last updated 7 years ago
Overview
- Description
- Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:gnu:groff:1.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "35017C15-4CCD-4B44-9108-F5650319A009" }, { "criteria": "cpe:2.3:a:gnu:groff:1.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B8AC4613-F1BE-4EEE-84C3-A13D2AC048B8" }, { "criteria": "cpe:2.3:a:gnu:groff:1.11a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D6BD17C-0DE9-405D-BC02-E996FBC4F97A" }, { "criteria": "cpe:2.3:a:gnu:groff:1.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5493392A-B8E1-4F71-A1ED-6889FD1CC217" }, { "criteria": "cpe:2.3:a:gnu:groff:1.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BDF86410-1841-4549-A0FE-3D16C6CCE383" }, { "criteria": "cpe:2.3:a:gnu:groff:1.16.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EDB1389A-0F7D-4616-8553-AF1E40B05256" }, { "criteria": "cpe:2.3:a:jgroff:jgroff:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9687B381-9EC4-45DB-A9A2-9AAFC6BF9D3A" } ], "operator": "OR" } ] } ]