CVE-2009-1962
published 2009-06-08CVE-2009-1962: Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3)…
PriorityP417medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.33%
25.8th percentile
Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or (11) xfig-spell.[PID] temporary files, where [PID] is a process ID.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xfig | < xfig 1:3.2.5.a-1 (bookworm) | xfig 1:3.2.5.a-1 (bookworm) |
| xfig | xfig | — | — |
| xfig | xfig | >= 0 < 1:3.2.5.a-1 | 1:3.2.5.a-1 |
| xfig | xfig | >= 0 < 1:3.2.5.a-1 | 1:3.2.5.a-1 |
| xfig | xfig | >= 0 < 1:3.2.5.a-1 | 1:3.2.5.a-1 |
| xfig | xfig | >= 0 < 1:3.2.5.a-1 | 1:3.2.5.a-1 |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xfig: insecure use of temporary files
vendor_redhat·2009-04-01·CVSS 4.4
CVE-2009-1962 [MEDIUM] xfig: insecure use of temporary files
xfig: insecure use of temporary files
Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or (11) xfig-spell.[PID] temporary files, where [PID] is a process ID.
Package: xfig (Red Hat Enterprise Linux 4) - Will not fix
Package: xfig (Red Hat Enterprise Linux 5) - Will not fix
Package: xfig (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2009-1962: xfig - Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a...
vendor_debian·2009·CVSS 4.4
CVE-2009-1962 [MEDIUM] CVE-2009-1962: xfig - Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a...
Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or (11) xfig-spell.[PID] temporary files, where [PID] is a process ID.
Scope: local
bookworm: resolved (fixed in 1:3.2.5.a-1)
bullseye: resolved (fixed in 1:3.2.5.a-1)
forky: resolved (fixed in 1:3.2.5.a-1)
sid: resolved (fixed in 1:3.2.5.a-1)
trixie: resolved (fixed in 1:3.2.5.a-1)
GHSA
GHSA-5fvh-wp4h-m832: Xfig, possibly 3
ghsa_unreviewed·2022-05-02
CVE-2009-1962 [MEDIUM] CWE-59 GHSA-5fvh-wp4h-m832: Xfig, possibly 3
Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or (11) xfig-spell.[PID] temporary files, where [PID] is a process ID.
OSV
CVE-2009-1962: Xfig, possibly 3
osv·2009-06-08·CVSS 4.4
CVE-2009-1962 [MEDIUM] CVE-2009-1962: Xfig, possibly 3
Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or (11) xfig-spell.[PID] temporary files, where [PID] is a process ID.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/35320http://www.mandriva.com/security/advisories?name=MDVSA-2009:244http://www.openwall.com/lists/oss-security/2009/04/01/6http://www.securityfocus.com/bid/34328https://exchange.xforce.ibmcloud.com/vulnerabilities/49600http://secunia.com/advisories/35320http://www.mandriva.com/security/advisories?name=MDVSA-2009:244http://www.openwall.com/lists/oss-security/2009/04/01/6http://www.securityfocus.com/bid/34328https://exchange.xforce.ibmcloud.com/vulnerabilities/49600
2009-06-08
Published