Junglewise Threat Intelligence

CVE-1999-1313: FreeBSD man utility privilege escalation

CVE-1999-1313 · Severity: medium · CVSS 4.6 · Published 1996-05-23

Technologies: FreeBSD Project Freebsd.

Executive brief

A vulnerability in the manual page reader (man) of FreeBSD 2.2 and earlier allows local users to gain elevated system privileges. The manual page reader is a standard utility used to view documentation for command-line tools. An attacker with an existing account on the system could exploit this flaw to bypass security restrictions and potentially take full control of the machine.

Technical details

A privilege escalation vulnerability exists in the 'man' utility of FreeBSD 2.2 and earlier. The flaw allows a local, unprivileged user to execute a specific sequence of commands that leverages the utility's elevated execution context to gain higher privileges (typically root or man-user privileges). While the exact mechanism (such as a buffer overflow or insecure temporary file handling) is not detailed in the summary, the vulnerability is triggered locally. A patch was released by the FreeBSD Project in advisory FreeBSD-SA-96:11.man.asc.

Affected products

  • FreeBSD Project FreeBSD 2.2 and earlier

Timeline

  • 1996-05-23: disclosed: Initial publication of the vulnerability.
  • 1996-05-23: advisory: FreeBSD Security Advisory FreeBSD-SA-96:11.man.asc released.

References