mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.
Software | From | Fixed in |
---|---|---|
debian / debian_linux | 2.2 | 2.2.x |
progeny / debian | 1.0 | 1.0.x |