CVE-2000-0803
published 2000-12-19CVE-2000-0803: GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a…
PriorityP426critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.33%
81.5th percentile
GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is executed when another user runs groff.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | groff | < 1.17 | 1.17 |
| chrome_chrome | — | — | |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wph5-jqqm-rqpf: GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a
ghsa_unreviewed·2022-04-30
CVE-2000-0803 [HIGH] GHSA-wph5-jqqm-rqpf: GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a
GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is executed when another user runs groff.
Chrome
Stable Channel Update for Desktop: CVE-2022-0803
vendor_chrome·2022-03-01·CVSS 6.5
CVE-2022-0803 [MEDIUM] Stable Channel Update for Desktop: CVE-2022-0803
Stable Channel Update for Desktop
CVE-2022-0803: Inappropriate implementation in Permissions. Reported by Abdulla Aldoseri on 2021-12-15 [$2500][ 1264561 ] Medium CVE-2022-0804: Inappropriate implementation in Full screen mode
Reported by Irvan Kurniawan (sourc7) on 2021-10-29 [$2000][ 1290700 ] Medium CVE-2022-0805: Use after free in Browser Switcher
Severity: medium
Microsoft
CVE-2000-0803: NIST NVD Details: https://nvd
vendor_msrc·2020-09-08·CVSS 10.0
CVE-2000-0803 [CRITICAL] CVE-2000-0803: NIST NVD Details: https://nvd
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2000-0803
Mariner: Mariner
[email protected]: [email protected]
Exploit Status: DOS:N/A
Remediation: groff
No detection rules found.
No writeups or analysis indexed.
2000-12-19
Published