Improper File Management in GNU Troff on Openwall GNU/Linux
CVE-2009-5082

Currently unrated

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
30 June 2011

Summary

The configure and config.guess scripts in GNU Troff version 1.20.1 on Openwall GNU/Linux improperly handle the creation of temporary files. Upon failure of the mktemp function, these scripts allow local users to perform a symlink attack, enabling them to overwrite arbitrary files. This vulnerability underscores the importance of secure temporary file management to mitigate unauthorized access and file integrity issues.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.