The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1336
Reference (s):
- BID:79723
- URL: http://www.securityfocus.com/bid/79723
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=840357
- GENTOO:GLSA-201707-12
- URL: https://security.gentoo.org/glsa/201707-12

