man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which could allow local users to gain privileges.
https://exchange.xforce.ibmcloud.com/vulnerabilities/12848
http://www.securityfocus.com/bid/8352