CVE-2009-5079

CWE-597 documents6 sources
Severity
3.3LOW
EPSS
0.0%
top 89.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 30
Latest updateMay 2

Description

The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU troff (aka groff) 1.21 and earlier allow local users to overwrite arbitrary files via a symlink attack on a gro#####.tmp or /tmp/##### temporary file.

CVSS vector

AV:L/AC:M/C:N/I:P/A:PExploitability: 3.4 | Impact: 4.9

Affected Packages2 packages

Debiangroff< 1.20.1-5+3
NVDgnu/groff1.21+15

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xq95-4rwq-mppc: The (1) gendef2022-05-02
OSV
CVE-2009-5079: The (1) gendef2011-06-30
CVEList
CVE-2009-5079: The (1) gendef2011-06-30

📋Vendor Advisories

3
Debian
CVE-2009-5079: groff - The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in...2009
Red Hat
gdm not built with tcp_wrappers2007-05-11
Red Hat
CVE-2009-5079: The (1) gendef
CVE-2009-5079 (LOW CVSS 3.3) | The (1) gendef.sh | cvebase.io