VULNERABILITY INTELLIGENCE

CVE-2000-0803

CVSS score10 HIGH
EPSS probability2.33%
CISA KEVNot currently listed
Published2000-12-19
Last modified2026-09-23
CVSS vectorAV:N/AC:L/Au:N/C:C/I:C/A:C

Description

GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is executed when another user runs groff.

Primary references