Lucene search

K
cve[email protected]CVE-2009-5082
HistoryOct 03, 2022 - 4:24 p.m.

CVE-2009-5082

2022-10-0316:24:01
CWE-59
web.nvd.nist.gov
25
gnu troff
groff
1.20.1
security vulnerability
symlink attack

3.3 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

6.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file.

Affected configurations

NVD
Node
gnugroffMatch1.20.1
AND
openwallowl
CPENameOperatorVersion
gnu:groffgnu groffeq1.20.1

3.3 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

6.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%