Local File Overwrite Vulnerability in GNU Troff by The GNU Project
CVE-2009-5079
Currently unrated
What is CVE-2009-5079?
The GNU Troff, also known as groff, prior to version 1.21, comprises scripts including gendef.sh, fixinfo.sh, and runtests.in that are susceptible to a local file overwrite vulnerability. This occurs when a local user exploits a symlink attack on temporary files created by the system. By manipulating the symbolic links, an attacker can overwrite arbitrary files, potentially compromising system integrity and user data.