Vulnerability Description
man-db before 2.8.5 on Gentoo allows local users (with access to the man user account) to gain root privileges because /usr/bin/mandb is executed by root but not owned by root. (Also, the owner can strip the setuid and setgid bits.)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Man-Db Project | Man-Db | < 2.8.5 |
Related Weaknesses (CWE)
References
- https://bugs.gentoo.org/662438ExploitVendor Advisory
- https://security.gentoo.org/glsa/202310-08
- https://bugs.gentoo.org/662438ExploitVendor Advisory
- https://security.gentoo.org/glsa/202310-08
FAQ
What is CVE-2018-25078?
CVE-2018-25078 is a vulnerability with a CVSS score of 7.8 (HIGH). man-db before 2.8.5 on Gentoo allows local users (with access to the man user account) to gain root privileges because /usr/bin/mandb is executed by root but not owned by root. (Also, the owner can st...
How severe is CVE-2018-25078?
CVE-2018-25078 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25078?
Check the references section above for vendor advisories and patch information. Affected products include: Man-Db Project Man-Db.