VULNERABILITY INTELLIGENCE
CVE-2000-0803
CVSS score10 HIGH
EPSS probability2.33%
CISA KEVNot currently listed
Published2000-12-19
Last modified2026-09-23
CVSS vectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Description
GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is executed when another user runs groff.
Primary references
- cve@mitre.org — VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — VDB Entry