PT-2011-1199 · Gnu+1 · Groff+1
Nico Golde
·
Published
2011-06-30
·
Updated
2024-06-15
·
CVE-2009-5080
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
groff versions prior to 1.22.2
Description
The issue affects the groff package in Gentoo Linux and concerns multiple vulnerabilities that can be exploited remotely, potentially leading to a breach of data integrity and availability. Specifically, in GNU troff (also known as groff) version 1.21 and earlier, certain scripts do not properly handle failed attempts to create temporary directories. This could allow local users to overwrite arbitrary files via a symlink attack on a file in a temporary directory. The affected scripts include
eqn2graph.sh, grap2graph.sh, and pic2graph.sh.Recommendations
For groff versions prior to 1.22.2, update to version 1.22.2 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
eqn2graph.sh, grap2graph.sh, and pic2graph.sh scripts until a patch is available.Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Groff