The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published: 2017-09-27T15:00:00

Updated: 2024-08-06T04:40:18.328Z

Reserved: 2015-01-22T00:00:00

Link: CVE-2015-1336

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-09-28T01:29:00.420

Modified: 2017-10-11T13:47:13.350

Link: CVE-2015-1336

cve-icon Redhat

Severity : Moderate

Publid Date: 2015-12-13T00:00:00Z

Links: CVE-2015-1336 - Bugzilla