Security Advisory Updated man packages fix minor vulnerability

Advisory: RHSA-2003:133-05
Type: Security Advisory
Severity: N/A
Issued on: 2003-05-01
Last updated on: 2003-05-01
Affected Products: Red Hat Linux 7.1
Red Hat Linux 7.2
Red Hat Linux 7.3
Red Hat Linux 8.0
OVAL: N/A
CVEs (cve.mitre.org): CVE-2003-0124

Details

Updated man packages fix a minor security vulnerability.

The man package includes tools for finding and displaying online documentation.

Versions of man before 1.51 have a bug where a malformed man file can cause
a program named "unsafe" to be run. To exploit this vulnerability a local
attacker would need to be able to get a victim to run man on a carefully
crafted man file, and for the attacker to be able to create a file called
"unsafe" that will be on the victims default path.

Red Hat Linux 7.1, 7.2, 7.3, and 8.0 are vulnerable to this issue. Users
of man can upgrade to these erratum packages which contain a patch to
correct this vulnerability. These erratum packages also contain fixes for
a number of other bugs.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Linux 7.1

SRPMS:
ftp://updates.redhat.com/7.1/en/os/SRPMS/man-1.5j-7.7x.0.src.rpm
Missing file
    73ec668993191b2f2324468faf9b6f66
 
IA-32:
ftp://updates.redhat.com/7.1/en/os/i386/man-1.5j-7.7x.0.i386.rpm
Missing file
    749524bab3e6baa60edbc71892e2bafd
 
Red Hat Linux 7.2

SRPMS:
ftp://updates.redhat.com/7.2/en/os/SRPMS/man-1.5j-7.7x.0.src.rpm
Missing file
    73ec668993191b2f2324468faf9b6f66
 
IA-32:
ftp://updates.redhat.com/7.2/en/os/i386/man-1.5j-7.7x.0.i386.rpm
Missing file
    749524bab3e6baa60edbc71892e2bafd
 
IA-64:
ftp://updates.redhat.com/7.2/en/os/ia64/man-1.5j-7.7x.0.ia64.rpm
Missing file
    7717002ab88fe9848ce67fe2cc670e6b
 
Red Hat Linux 7.3

SRPMS:
ftp://updates.redhat.com/7.3/en/os/SRPMS/man-1.5j-7.7x.0.src.rpm
Missing file
    73ec668993191b2f2324468faf9b6f66
 
IA-32:
ftp://updates.redhat.com/7.3/en/os/i386/man-1.5j-7.7x.0.i386.rpm
Missing file
    749524bab3e6baa60edbc71892e2bafd
 
Red Hat Linux 8.0

SRPMS:
ftp://updates.redhat.com/8.0/en/os/SRPMS/man-1.5k-0.8x.0.src.rpm
Missing file
    a682e5aad64a9dcdf54373b3870c2460
 
IA-32:
ftp://updates.redhat.com/8.0/en/os/i386/man-1.5k-0.8x.0.i386.rpm
Missing file
    c12cf9900a6952bb3739a374ad36aed1
 

Bugs fixed (see bugzilla for more information)

62606 - apropos (man -k) generating invalid grep arguments
65467 - /etc/man.config should MANPATH_MAP /usr/local/share/man
65511 - makewhatis man page omitted from specfile.
77847 - man in Red Hat 8.0 assumes groff 1.18, but doesn't require it
79289 - man -k attempts to run 'unsafe' script
81964 - man uses wrong config file
82088 - Mark /etc/man.config as %config(noreplace)
82684 - /usr/bin/whatis fails with a grep error
83934 - man command needs Korean man pages support


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/