CVE-2001-1022
published 2001-07-26CVE-2001-1022: Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and…
PriorityP346high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
11.44%
95.5th percentile
Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fj6r-7wmg-qvf3: Format string vulnerability in pic utility in groff 1
ghsa_unreviewed·2022-04-30
CVE-2001-1022 [HIGH] GHSA-fj6r-7wmg-qvf3: Format string vulnerability in pic utility in groff 1
Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.
Red Hat
security flaw
vendor_redhat·2001-07-27·CVSS 7.5
CVE-2001-1022 [HIGH] security flaw
security flaw
Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.
No detection rules found.
Exploit-DB
GNU groff 1.1x - xploitation Via LPD
exploitdb·2001-06-23
CVE-2001-1022 GNU groff 1.1x - xploitation Via LPD
GNU groff 1.1x - xploitation Via LPD
---
// source: https://www.securityfocus.com/bid/3103/info
lpd is the print spooling daemon. It is used to support network printing on a variety of unix platforms.
The version of lpd that ships with linux systems invokes groff to process documents that are to be printed. The groff utility used to process images, 'pic', contains a vulnerability that can be exploited to execute arbitrary commands on the victim.
It may be possible for remote attackers to exploit this vulnerability through lpd.
#include
///////////////////////////////////////////////////////////////////
/// // // /// //// //// // //////______/
/// // // ////// / / / /// //// //// //// //////////______/
/// /// /// // // /// //// //// //// /////// ///
/// // // ////// ///// /// //// //
Exploit-DB
Trend Micro Interscan VirusWall 3.2.3/3.3 - 'HELO' Remote Buffer Overflow (1)
exploitdb·1999-11-07
CVE-2001-0679 Trend Micro Interscan VirusWall 3.2.3/3.3 - 'HELO' Remote Buffer Overflow (1)
Trend Micro Interscan VirusWall 3.2.3/3.3 - 'HELO' Remote Buffer Overflow (1)
---
source: https://www.securityfocus.com/bid/787/info
There is a buffer overflow in the HELO command of the smtp gateway which ships as part of the VirusWall product. This buffer overflow could be used to launch arbitrary code on the vulnerable server.
This issue was patched by InterScan, however even with the patch it is possible to cause a DoS of the mail server software by sending between 4075 and 4090 characters.
#!/usr/bin/perl
# (c) Alain Thivillon & Stephane Aubert
# Herve Schauer Consultants 2000
# http://www.hsc.fr/
#
# Do not use this stuff against Microsoft MX hosts :)
#
# Crash Interscan SMTP Server on Windows NT Version 3.32 Builds 1011 and 1022
# Depending of debugger installed on NT, crash c
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000428http://www.debian.org/security/2001/dsa-072http://www.debian.org/security/2002/dsa-107http://www.osvdb.org/1914http://www.redhat.com/support/errata/RHSA-2002-004.htmlhttp://www.securityfocus.com/archive/1/199706http://www.securityfocus.com/bid/3103https://exchange.xforce.ibmcloud.com/vulnerabilities/6918http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000428http://www.debian.org/security/2001/dsa-072http://www.debian.org/security/2002/dsa-107http://www.osvdb.org/1914http://www.redhat.com/support/errata/RHSA-2002-004.htmlhttp://www.securityfocus.com/archive/1/199706http://www.securityfocus.com/bid/3103https://exchange.xforce.ibmcloud.com/vulnerabilities/6918
2001-07-26
Published