Xman does not drop privileges even though it is installed with the suid bit. This allows a local attacker exploiting system calls to overflow the internal MANPATH buffer allowing execution of arbitrary commands.
Credit:
The information has been provided by v9 (a.k.a. Vade79).