3.3
CVSSv2

CVE-2009-5080

Published: 30/06/2011 Updated: 07/11/2023
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib/pic2graph/pic2graph.sh scripts in GNU troff (aka groff) 1.21 and previous versions do not properly handle certain failed attempts to create temporary directories, which might allow local users to overwrite arbitrary files via a symlink attack on a file in a temporary directory, a different vulnerability than CVE-2004-1296.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu groff

gnu groff 1.16.1

gnu groff 1.16

gnu groff 1.19.2

gnu groff 1.18.1

gnu groff 1.11a

gnu groff 1.19.1

gnu groff 1.20

gnu groff 1.19

gnu groff 1.20.1

gnu groff 1.14

gnu groff 1.17.2

gnu groff 1.10

gnu groff 1.17.1

gnu groff 1.11

gnu groff 1.15

Github Repositories

A small Go application that allows scraping of Vuls reports by Prometheus.

prometheus-vuls-exporter prometheus-vuls-exporter is a small Go application that allows scraping of Vuls reports by Prometheus Exported metrics This exporter exposes the following metrics: # HELP reported_at Timestamp of last report time, in ms since Unix # TYPE reported_at gauge reported_at 158896003e+09 # HELP server_count Total count of servers reported # TYPE server_count