Local File Overwrite Vulnerability in GNU Troff by The GNU Project
CVE-2009-5079

Currently unrated

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
30 June 2011

Summary

The GNU Troff, also known as groff, prior to version 1.21, comprises scripts including gendef.sh, fixinfo.sh, and runtests.in that are susceptible to a local file overwrite vulnerability. This occurs when a local user exploits a symlink attack on temporary files created by the system. By manipulating the symbolic links, an attacker can overwrite arbitrary files, potentially compromising system integrity and user data.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.