PT-2007-6873 · Feynmf · Feynmf
Kevin B. Mccarty
·
Published
2007-11-13
·
Updated
2011-03-08
·
CVE-2007-5940
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
feynmf version 1.08
Description
The issue allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the
feynmf$$.pl temporary file. This is related to the feynmf.pl script in feynmf, which is used in TeXLive 2007.Recommendations
For feynm version 1.08, consider restricting access to the
feynmf.pl script until a patch is available. As a temporary workaround, avoid using the feynmf.pl script to minimize the risk of exploitation.Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Feynmf