Description
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:LExploitability: 3.9 | Impact: 2.5Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: Low
Availability: Low
Affected Packages3 packages
🔴Vulnerability Details
3GHSAGHSA-pg77-m46r-9ph2: contrib/pdfmark/pdfroff↗2022-05-03 ▶ OSVCVE-2009-5078: contrib/pdfmark/pdfroff↗2011-06-30 ▶ CVEListCVE-2009-5078: contrib/pdfmark/pdfroff↗2011-06-30 ▶ 📋Vendor Advisories
3Red Hatgroff: pdfroff.sh launches Ghostscript without -dSAFER↗2009-07-24 ▶ DebianCVE-2009-5078: groff - contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Gho...↗2009 ▶ AppleCVE-2009-5078: OS X Yosemite v10.10.5 and Security Update 2015-006↗ ▶ 💬Community
2BugzillaCVE-2009-5078 groff: pdfroff.sh launches Ghostscript without -dSAFER↗2011-07-08 ▶ BugzillaCVE-2009-5078 groff: pdfroff.sh launches Ghostscript without -dSAFER [fedora-14]↗2011-07-08 ▶