Red Hat Bugzilla – Bug 4221
Possible root compromises via man/groff.
Last modified: 2008-05-01 11:37:51 EDT
The RPMs for groff that come with RH 6.0 apply a patch,
groff-1.11-safer.patch, which removes the unsafe groff
It is possible that the unsafe commands could find their way
back in should the user decide to rebuild groff and not take
the time to kill the unsafe commands. This situation can be
avoided by changing the /etc/man.config file. The TROFF and
NROFF lines should be modified to include the -S flag,
indicating that the "safer" mode of groff should be used for
formatting man pages.
If someone rebuilds groff and introduces a security hole, then they
are putting themselves at risk. adding the -S field to
/etc/man.config will only move the problem around -- other
applications / uses of groff will still have the hole. This not truly
lead to better security.
We do not recommend that people rebuild packages unless they are very
sure they understand what they are doing.