PT-2011-1199 · Gnu+1 · Groff+1

Nico Golde

·

Published

2011-06-30

·

Updated

2024-06-15

·

CVE-2009-5080

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions groff versions prior to 1.22.2
Description The issue affects the groff package in Gentoo Linux and concerns multiple vulnerabilities that can be exploited remotely, potentially leading to a breach of data integrity and availability. Specifically, in GNU troff (also known as groff) version 1.21 and earlier, certain scripts do not properly handle failed attempts to create temporary directories. This could allow local users to overwrite arbitrary files via a symlink attack on a file in a temporary directory. The affected scripts include eqn2graph.sh, grap2graph.sh, and pic2graph.sh.
Recommendations For groff versions prior to 1.22.2, update to version 1.22.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the eqn2graph.sh, grap2graph.sh, and pic2graph.sh scripts until a patch is available.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1079
BDU:2015-09687
CVE-2009-5080
OPENSUSE-SU-2024:10031-1

Affected Products

Alt Linux
Groff