ZeroHour

CVE-2000-0803

CVSS 2.0
10.0 high
EPSS
Published
()
Modified
Description

GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is executed when another user runs groff.

Vendors
gnu
Products
groff
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C

In the news

No ingested article mentions this CVE yet.