CVE-2004-0969
published 2005-02-09CVE-2004-0969: The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.38%
29.7th percentile
The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | groff | < groff 1.20.1-5 (bookworm) | groff 1.20.1-5 (bookworm) |
| debian | groff | < groff 1.18.1.1-2 (bookworm) | groff 1.18.1.1-2 (bookworm) |
| gnu | groff | <= 1.21 | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
| gnu | groff | >= 0 < 1.18.1.1-2 | 1.18.1.1-2 |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
| gnu | groff | >= 0 < 1.18.1.1-2 | 1.18.1.1-2 |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
| gnu | groff | >= 0 < 1.18.1.1-2 | 1.18.1.1-2 |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
groff: roff2.pl and groffer.pl use easy-to-guess temporary file names
vendor_redhat·2009-08-14·CVSS 2.1
CVE-2009-5081 [LOW] CWE-377 groff: roff2.pl and groffer.pl use easy-to-guess temporary file names
groff: roff2.pl and groffer.pl use easy-to-guess temporary file names
The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969.
Statement: Not vulnerable. This issue did not affect the versions of groff as shipped with
Red Hat Enterprise Linux 4, 5, or 6.
Debian
CVE-2009-5081: groff - The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groff...
vendor_debian·2009·CVSS 2.1
CVE-2009-5081 [LOW] CVE-2009-5081: groff - The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groff...
The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969.
Scope: local
bookworm: resolved (fixed in 1.20.1-5)
bullseye: resolved (fixed in 1.20.1-5)
forky: resolved (fixed in 1.20.1-5)
sid: resolved (fixed in 1.20.1-5)
trixie: resolved (fixed in 1.20.1-5)
Ubuntu
groff utility vulnerability
vendor_ubuntu·2004-11-02
CVE-2004-0969 groff utility vulnerability
Title: groff utility vulnerability
Summary: groff utility vulnerability
Recently, Trustix Secure Linux discovered a vulnerability in the groff
package. The utility "groffer" created a temporary directory in an
insecure way, which allowed exploitation of a race condition to create
or overwrite files with the privileges of the user invoking the
program.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2004-0969: groff - The groffer script in the Groff package 1.18 and later versions, as used in Trus...
vendor_debian·2004·CVSS 2.1
CVE-2004-0969 [LOW] CVE-2004-0969: groff - The groffer script in the Groff package 1.18 and later versions, as used in Trus...
The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
Scope: local
bookworm: resolved (fixed in 1.18.1.1-2)
bullseye: resolved (fixed in 1.18.1.1-2)
forky: resolved (fixed in 1.18.1.1-2)
sid: resolved (fixed in 1.18.1.1-2)
trixie: resolved (fixed in 1.18.1.1-2)
GHSA
GHSA-8mmw-rg27-gmpp: The (1) config
ghsa_unreviewed·2022-05-02·CVSS 2.1
CVE-2009-5081 [LOW] CWE-59 GHSA-8mmw-rg27-gmpp: The (1) config
The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969.
GHSA
GHSA-r5c9-rvx3-whrv: The groffer script in the Groff package 1
ghsa_unreviewed·2022-04-29
CVE-2004-0969 [LOW] GHSA-r5c9-rvx3-whrv: The groffer script in the Groff package 1
The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
OSV
CVE-2009-5081: The (1) config
osv·2011-06-30·CVSS 2.1
CVE-2009-5081 [LOW] CVE-2009-5081: The (1) config
The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969.
OSV
CVE-2004-0969: The groffer script in the Groff package 1
osv·2005-02-09·CVSS 2.1
CVE-2004-0969 [LOW] CVE-2004-0969: The groffer script in the Groff package 1
The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
No detection rules found.
No public exploits indexed.
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136313http://secunia.com/advisories/18764http://www.gentoo.org/security/en/glsa/glsa-200411-15.xmlhttp://www.securityfocus.com/bid/11287http://www.trustix.org/errata/2004/0050http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:038https://exchange.xforce.ibmcloud.com/vulnerabilities/17583http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136313http://secunia.com/advisories/18764http://www.gentoo.org/security/en/glsa/glsa-200411-15.xmlhttp://www.securityfocus.com/bid/11287http://www.trustix.org/errata/2004/0050http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:038https://exchange.xforce.ibmcloud.com/vulnerabilities/17583
2005-02-09
Published