CVE-2001-1022 is a format string vulnerability in the pic utility of GNU groff (versions 1.16.1 and others) and jgroff (before 1.15). This flaw allows remote attackers to bypass security restrictions and execute arbitrary commands by injecting format string specifiers into the plot command. It carries a CVSS score of 7.5 (High), indicating a network-based attack with low complexity that can lead to partial compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, an ExploitDB entry (EDB-21037) exists, and it has garnered significant community discussion, suggesting potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.10CPE matchmatch criteria | cpe:2.3:a:gnu:groff:1.10:*:*:*:*:*:*:* | ||
1.11CPE matchmatch criteria | cpe:2.3:a:gnu:groff:1.11:*:*:*:*:*:*:* | ||
1.11aCPE matchmatch criteria | cpe:2.3:a:gnu:groff:1.11a:*:*:*:*:*:*:* | ||
1.14CPE matchmatch criteria | cpe:2.3:a:gnu:groff:1.14:*:*:*:*:*:*:* | ||
1.15CPE matchmatch criteria | cpe:2.3:a:gnu:groff:1.15:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.