CVE-2009-5082
published 2011-06-30CVE-2009-5082: The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a…
PriorityP49low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
0.32%
23.9th percentile
The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | groff | < groff 1.20.1-5 (bookworm) | groff 1.20.1-5 (bookworm) |
| gnu | groff | — | — |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
| gnu | groff | >= 0 < 1.20.1-5 | 1.20.1-5 |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6ww7-mx3f-8cq3: The (1) configure and (2) config
ghsa_unreviewed·2022-05-02
CVE-2009-5082 [LOW] CWE-59 GHSA-6ww7-mx3f-8cq3: The (1) configure and (2) config
The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file.
OSV
CVE-2009-5082: The (1) configure and (2) config
osv·2011-06-30·CVSS 3.3
CVE-2009-5082 [LOW] CVE-2009-5082: The (1) configure and (2) config
The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file.
Debian
CVE-2009-5082: groff - The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 o...
vendor_debian·2009·CVSS 3.3
CVE-2009-5082 [LOW] CVE-2009-5082: groff - The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 o...
The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file.
Scope: local
bookworm: resolved (fixed in 1.20.1-5)
bullseye: resolved (fixed in 1.20.1-5)
forky: resolved (fixed in 1.20.1-5)
sid: resolved (fixed in 1.20.1-5)
trixie: resolved (fixed in 1.20.1-5)
Red Hat
CVE-2009-5082: The (1) configure and (2) config
vendor_redhat·CVSS 3.3
CVE-2009-5082 [LOW] CVE-2009-5082: The (1) configure and (2) config
The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact because it can only be exploited during package compilation. We do not currently plan to fix this flaw.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diffhttp://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diff.diff?r1=1.1%3Br2=1.2%3Bf=hhttp://openwall.com/lists/oss-security/2009/08/14/4http://openwall.com/lists/oss-security/2009/08/14/5http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diffhttp://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diff.diff?r1=1.1%3Br2=1.2%3Bf=hhttp://openwall.com/lists/oss-security/2009/08/14/4http://openwall.com/lists/oss-security/2009/08/14/5
2011-06-30
Published