Local File Overwrite Vulnerability in GNU Troff by Free Software Foundation
CVE-2009-5080

Currently unrated

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
30 June 2011

Summary

The scripts contrib/eqn2graph/eqn2graph.sh, contrib/grap2graph/grap2graph.sh, and contrib/pic2graph/pic2graph.sh in GNU Troff versions 1.21 and earlier do not adequately handle failed attempts to create temporary directories. This flaw may allow local users to exploit a symlink attack, potentially overwriting arbitrary files in a temporary directory. Users should ensure they are using the latest version of the software to mitigate the associated risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.