Local File Overwrite Vulnerability in GNU Troff by Free Software Foundation
CVE-2009-5080
Currently unrated
Summary
The scripts contrib/eqn2graph/eqn2graph.sh, contrib/grap2graph/grap2graph.sh, and contrib/pic2graph/pic2graph.sh in GNU Troff versions 1.21 and earlier do not adequately handle failed attempts to create temporary directories. This flaw may allow local users to exploit a symlink attack, potentially overwriting arbitrary files in a temporary directory. Users should ensure they are using the latest version of the software to mitigate the associated risks.
References
Timeline
Vulnerability published
Vulnerability Reserved