CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:L/AC:L/Au:N/C:N/I:P/A:N
AI Score
Confidence
Low
EPSS
Percentile
5.1%
The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
Vendor | Product | Version | CPE |
---|---|---|---|
gnu | a2ps | 4.13 | cpe:2.3:a:gnu:a2ps:4.13:*:*:*:*:*:*:* |
gnu | a2ps | 4.13b | cpe:2.3:a:gnu:a2ps:4.13b:*:*:*:*:*:*:* |
turbolinux | turbolinux_home | * | cpe:2.3:o:turbolinux:turbolinux_home:*:*:*:*:*:*:*:* |
turbolinux | turbolinux_server | 7.0 | cpe:2.3:o:turbolinux:turbolinux_server:7.0:*:*:*:*:*:*:* |
turbolinux | turbolinux_server | 8.0 | cpe:2.3:o:turbolinux:turbolinux_server:8.0:*:*:*:*:*:*:* |
turbolinux | turbolinux_workstation | 7.0 | cpe:2.3:o:turbolinux:turbolinux_workstation:7.0:*:*:*:*:*:*:* |
turbolinux | turbolinux_workstation | 8.0 | cpe:2.3:o:turbolinux:turbolinux_workstation:8.0:*:*:*:*:*:*:* |
secunia.com/advisories/13641
www.gentoo.org/security/en/glsa/glsa-200501-02.xml
www.securityfocus.com/bid/12108
www.securityfocus.com/bid/12109
www.vuxml.org/freebsd/9168253c-5a6d-11d9-a9e7-0001020eed82.html
exchange.xforce.ibmcloud.com/vulnerabilities/18671
exchange.xforce.ibmcloud.com/vulnerabilities/18672