CVE-2009-5078
published 2011-06-30CVE-2009-5078: contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to…
PriorityP335medium6.5CVSS 3.0
AVNACLPRNUINSUCNILAL
EPSS
2.31%
81.3th percentile
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.4 | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | groff | < groff 1.20.1-5 (bookworm) | groff 1.20.1-5 (bookworm) |
| gnu | groff | <= 1.20.1 | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | — | — |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pg77-m46r-9ph2: contrib/pdfmark/pdfroff
ghsa_unreviewed·2022-05-03
CVE-2009-5078 [MEDIUM] GHSA-pg77-m46r-9ph2: contrib/pdfmark/pdfroff
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.
OSV
CVE-2009-5078: contrib/pdfmark/pdfroff
osv·2011-06-30·CVSS 6.5
CVE-2009-5078 [MEDIUM] CVE-2009-5078: contrib/pdfmark/pdfroff
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.
Red Hat
groff: pdfroff.sh launches Ghostscript without -dSAFER
vendor_redhat·2009-07-24·CVSS 6.5
CVE-2009-5078 [MEDIUM] groff: pdfroff.sh launches Ghostscript without -dSAFER
groff: pdfroff.sh launches Ghostscript without -dSAFER
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.
Statement: Not vulnerable. This issue did not affect the versions of groff as shipped with Red Hat Enterprise Linux 4, 5, or 6.
Debian
CVE-2009-5078: groff - contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Gho...
vendor_debian·2009·CVSS 6.5
CVE-2009-5078 [MEDIUM] CVE-2009-5078: groff - contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Gho...
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.
Scope: local
bookworm: resolved (fixed in 1.20.1-5)
bullseye: resolved (fixed in 1.20.1-5)
forky: resolved (fixed in 1.20.1-5)
sid: resolved (fixed in 1.20.1-5)
trixie: resolved (fixed in 1.20.1-5)
Apple
CVE-2009-5078: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 6.5
CVE-2009-5078 [MEDIUM] CVE-2009-5078: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2009-5078
Component: CVE-2009-5078
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-5078 groff: pdfroff.sh launches Ghostscript without -dSAFER
bugzilla·2011-07-08·CVSS 6.5
CVE-2009-5078 [MEDIUM] CVE-2009-5078 groff: pdfroff.sh launches Ghostscript without -dSAFER
CVE-2009-5078 groff: pdfroff.sh launches Ghostscript without -dSAFER
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-5078 to
the following vulnerability:
Name: CVE-2009-5078
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5078
Assigned: 20110630
Reference: http://openwall.com/lists/oss-security/2009/08/09/1
Reference: http://openwall.com/lists/oss-security/2009/08/10/2
Reference: ftp://ftp.gnu.org/gnu/groff/groff-1.20.1-1.21.diff.gz
Reference: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538338
Reference: http://www.securityfocus.com/bid/36381
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21
launches the Ghostscript program without the -dSAFER option, which
allows remote attackers to create, overwrite, rename, or delete
arbitrary files
Bugzilla
CVE-2009-5078 groff: pdfroff.sh launches Ghostscript without -dSAFER [fedora-14]
bugzilla·2011-07-08·CVSS 6.5
CVE-2009-5078 [MEDIUM] CVE-2009-5078 groff: pdfroff.sh launches Ghostscript without -dSAFER [fedora-14]
CVE-2009-5078 groff: pdfroff.sh launches Ghostscript without -dSAFER [fedora-14]
fedora-14 tracking bug for groff: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
This was fixed in F15+
ftp://ftp.gnu.org/gnu/groff/groff-1.20.1-1.21.diff.gzhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538338http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://openwall.com/lists/oss-security/2009/08/09/1http://openwall.com/lists/oss-security/2009/08/10/2http://www.securityfocus.com/bid/36381https://support.apple.com/kb/HT205031ftp://ftp.gnu.org/gnu/groff/groff-1.20.1-1.21.diff.gzhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538338http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://openwall.com/lists/oss-security/2009/08/09/1http://openwall.com/lists/oss-security/2009/08/10/2http://www.securityfocus.com/bid/36381https://support.apple.com/kb/HT205031
2011-06-30
Published