Back

CVE-2001-1022

Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.

Published: Jul 26, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (7)

Vendor Product Version
gnu groff 1.10
gnu groff 1.11
gnu groff 1.11a
gnu groff 1.14
gnu groff 1.15
gnu groff 1.16.1
jgroff jgroff *

GitHub Security Advisory GHSA-fj6r-7wmg-qvf3

Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 11.44%

Top 4% most likely to be exploited

Threat Score 33.4 / 100

Data Sources

NVD EPSS GitHub