Lucene search

K
freebsdFreeBSD01BB84E2-BD88-11D9-A281-02E018374E71
HistoryDec 20, 2004 - 12:00 a.m.

groff -- pic2graph and eqn2graph are vulnerable to symlink attack through temporary files

2004-12-2000:00:00
vuxml.freebsd.org
15

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

EPSS

0

Percentile

5.1%

The eqn2graph and pic2graph scripts in groff 1.18.1
allow local users to overwrite arbitrary files via
a symlink attack on temporary files.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchja-groff= 1.18.1UNKNOWN
FreeBSDanynoarchja-groff< 1.18.1_8UNKNOWN

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

EPSS

0

Percentile

5.1%

Related for 01BB84E2-BD88-11D9-A281-02E018374E71