J-Security Center

Title: Slackware Malicious Manual Page Cache File Creation Vulnerability

Severity: MODERATE

Description:

Slackware Linux contains a configuration error that enables local users to create files in the directory used by the system manual pager ('man') for cache files.

When a system manual page is viewed with the 'man' program, a cache file is created containing information relevant to the current state of the manual page system and the information stored within that page. The cache files are used by the manual pager to enhance the speed of subsequent page lookups.

Due to the behaviour of the 'man' program, it may be possible for an attacker to create a malicious cache file causing the execution of arbitrary code when another user views a manual page corresponding to that cache file.

Affected Products:

  • Slackware Linux 7.0.0
  • Slackware Linux 7.1.0
  • Slackware Linux 8.0.0

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.