Vulnerability Name: | CVE-2009-5079 (CCN-68432) |
Assigned: | 2009-08-14 |
Published: | 2009-08-14 |
Updated: | 2013-12-13 |
Summary: | The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU troff (aka groff) 1.21 and earlier allow local users to overwrite arbitrary files via a symlink attack on a gro#####.tmp or /tmp/##### temporary file.
|
CVSS v3 Severity: | 5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): Low |
|
CVSS v2 Severity: | 3.3 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P) 3.2 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:U/RC:UR)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Medium Authentication (Au): None | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): Partial | 3.3 Low (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P) 3.2 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:U/RC:UR)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Medium Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): Partial |
|
Vulnerability Type: | CWE-59
|
Vulnerability Consequences: | File Manipulation |
References: | Source: MITRE Type: CNA CVE-2009-5079
Source: CONFIRM Type: Patch http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diff
Source: CONFIRM Type: Patch http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diff.diff?r1=1.1;r2=1.2;f=h
Source: CCN Type: oss-security Mailing List, Fri, 14 Aug 2009 20:36:07 +0400 CVE id request: groff (pdfroff)
Source: MLIST Type: UNKNOWN [oss-security] 20090814 Re: CVE id request: groff (pdfroff)
Source: MLIST Type: Patch [oss-security] 20090814 Re: CVE id request: groff (pdfroff)
Source: CCN Type: GNU Troff Web site GNU Troff (Groff) - a GNU project
Source: MANDRIVA Type: UNKNOWN MDVSA-2013:085
Source: MANDRIVA Type: UNKNOWN MDVSA-2013:086
Source: CCN Type: OSVDB ID: 74383 GNU troff gendef.sh Multiple Temporary File Symlink Arbitrary File Overwrite
Source: CCN Type: OSVDB ID: 74384 GNU troff doc/fixinfo.sh Multiple Temporary File Symlink Arbitrary File Overwrite
Source: CCN Type: OSVDB ID: 74385 GNU troff contrib/gdiffmk/tests/runtests.in Multiple Temporary File Symlink Arbitrary File Overwrite
Source: XF Type: UNKNOWN groff-gendef-symlink(68432)
|
Vulnerable Configuration: | Configuration 1: cpe:/a:gnu:groff:1.10:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.11:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.11a:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.14:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.15:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.16:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.16.1:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.17.1:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.17.2:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.18.1:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.19:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.19.1:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.19.2:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.20:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.20.1:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:*:*:*:*:*:*:*:* (Version <= 1.21) Configuration CCN 1: cpe:/a:gnu:groff:1.10:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.11:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.11a:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.14:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.15:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.16:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.16.1:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.18.1:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.19:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.17.2:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.19.1:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.20.1:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.17.1:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.19.2:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.20:*:*:*:*:*:*:*OR cpe:/a:gnu:groff:1.21:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |