search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Linux groff utility pic contains format string vulnerability

Vulnerability Note VU#399883

Original Release Date: 2003-10-27 | Last Revised: 2003-10-28

Overview

The pic component of the image processing package groff contains a format string vulnerability that could allow a remote attacker to execute arbitrary code.

Description

groff is an image processing package on Linux systems. A component of groff called pic contains a format-string vulnerability that can be exploited to execute arbitrary code. Since groff and pic are used by lpd to render documents for printing, an attacker can craft a printer spool file to execute arbitrary code on an lpd print server.

Impact

Remote attackers can cause execution of arbitrary code.

Solution

Apply a patch or upgrade

Apply a patch or upgrade as appropriate. See the Systems Affected section for more details.

Vendor Information

399883
 

View all 27 vendors View less vendors


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to zen-parse for reporting this vulnerability.

This document was written by Shawn Van Ittersum and Art Manion.

Other Information

CVE IDs: CVE-2001-1022
Severity Metric: 10.80
Date Public: 2001-07-26
Date First Published: 2003-10-27
Date Last Updated: 2003-10-28 17:18 UTC
Document Revision: 13

Sponsored by CISA.