CVE-2009-5044
published 2011-06-24CVE-2009-5044: contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp…
PriorityP48low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
0.37%
29.5th percentile
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.4 | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | groff | < groff 1.20.1-5 (bookworm) | groff 1.20.1-5 (bookworm) |
| gnu | groff | <= 1.20.1 | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
groff: insecure temporary file handling in pdfroff
vendor_redhat·2009-07-24·CVSS 3.3
CVE-2009-5044 [LOW] CWE-377 groff: insecure temporary file handling in pdfroff
groff: insecure temporary file handling in pdfroff
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.
Statement: Not vulnerable. This issue did not affect the versions of groff as shipped with Red Hat Enterprise Linux 4, 5, or 6.
Package: groff (Red Hat Enterprise Linux 4) - Not affected
Package: groff (Red Hat Enterprise Linux 5) - Not affected
Package: groff (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2009-5044: groff - contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local use...
vendor_debian·2009·CVSS 3.3
CVE-2009-5044 [LOW] CVE-2009-5044: groff - contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local use...
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.
Scope: local
bookworm: resolved (fixed in 1.20.1-5)
bullseye: resolved (fixed in 1.20.1-5)
forky: resolved (fixed in 1.20.1-5)
sid: resolved (fixed in 1.20.1-5)
trixie: resolved (fixed in 1.20.1-5)
Apple
CVE-2009-5044: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 3.3
CVE-2009-5044 [LOW] CVE-2009-5044: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2009-5044
Component: CVE-2009-5044
GHSA
GHSA-f2wq-wrc8-9j57: contrib/pdfmark/pdfroff
ghsa_unreviewed·2022-05-03
CVE-2009-5044 [LOW] CWE-59 GHSA-f2wq-wrc8-9j57: contrib/pdfmark/pdfroff
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.
OSV
CVE-2009-5044: contrib/pdfmark/pdfroff
osv·2011-06-24·CVSS 3.3
CVE-2009-5044 [LOW] CVE-2009-5044: contrib/pdfmark/pdfroff
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-5044 groff: insecure temporary file handling in pdfroff [fedora-14]
bugzilla·2011-05-31·CVSS 3.3
CVE-2009-5044 [LOW] CVE-2009-5044 groff: insecure temporary file handling in pdfroff [fedora-14]
CVE-2009-5044 groff: insecure temporary file handling in pdfroff [fedora-14]
fedora-14 tracking bug for groff: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
I have added the fix into F15 and higher. No plans to fix this in F14.
Bugzilla
CVE-2009-5044 groff: insecure temporary file handling in pdfroff
bugzilla·2011-05-31·CVSS 3.3
CVE-2009-5044 [LOW] CVE-2009-5044 groff: insecure temporary file handling in pdfroff
CVE-2009-5044 groff: insecure temporary file handling in pdfroff
A Debian bug report [1] indicated that the pdfroff utility uses $$ (the current process's PID) to create predictable temporary files.
pdfroff is not included in older versions of groff as provided with Red Hat Enterprise Linux 6 or earlier (1.18.1), but is included in 1.20 and higher, so Fedora 14 and higher are affected.
As well, older groff includes the groff-1.18.1.4-sectmp.patch patch which fixes other temporary file issues, however Fedora 14 and higher do not include a similar patch. Recommend using the Openwall patch [2] in Fedora 14 and higher to secure this flaw and other temporary file issues that had previously been protected with the aforementioned patch.
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538
Bugzilla
CVE-2009-5044 groff: insecure temporary file handling in pdfroff [fedora-15]
bugzilla·2011-05-31·CVSS 3.3
CVE-2009-5044 [LOW] CVE-2009-5044 groff: insecure temporary file handling in pdfroff [fedora-15]
CVE-2009-5044 groff: insecure temporary file handling in pdfroff [fedora-15]
fedora-15 tracking bug for groff: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
groff-1.21-9.fc17 has been submitted as an update for Fedora 17.
https://admin.fedoraproject.org/updates/groff-1.21-9.fc17
---
Resolved in:
groff-1.21-4.fc15
groff-1.21-4.fc16
groff-1.21-9.fc17
groff-1.21-9.fc18
---
groff-1.21-4.fc15 has been submitted as an update for Fedora 15.
https://admin.fedoraproject.org/updates/groff-1.21-4.fc15
---
groff-1.21-4.fc16 has been submitted as an update for Fedora 16.
https://admin.fedoraproject.org/updates/groff-1
ftp://ftp.gnu.org/gnu/groff/groff-1.20.1-1.21.diff.gzhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538330http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diffhttp://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diff.diff?r1=1.1%3Br2=1.2%3Bf=hhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://openwall.com/lists/oss-security/2009/08/09/1http://openwall.com/lists/oss-security/2009/08/10/2http://openwall.com/lists/oss-security/2009/08/14/4http://openwall.com/lists/oss-security/2009/08/14/5http://secunia.com/advisories/44999http://www.mandriva.com/security/advisories?name=MDVSA-2013:085http://www.mandriva.com/security/advisories?name=MDVSA-2013:086http://www.securityfocus.com/bid/36381https://support.apple.com/kb/HT205031ftp://ftp.gnu.org/gnu/groff/groff-1.20.1-1.21.diff.gzhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538330http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diffhttp://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diff.diff?r1=1.1%3Br2=1.2%3Bf=hhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://openwall.com/lists/oss-security/2009/08/09/1http://openwall.com/lists/oss-security/2009/08/10/2http://openwall.com/lists/oss-security/2009/08/14/4http://openwall.com/lists/oss-security/2009/08/14/5http://secunia.com/advisories/44999http://www.mandriva.com/security/advisories?name=MDVSA-2013:085http://www.mandriva.com/security/advisories?name=MDVSA-2013:086http://www.securityfocus.com/bid/36381https://support.apple.com/kb/HT205031
2011-06-24
Published