3.3
CVSSv2

CVE-2009-5081

Published: 30/06/2011 Updated: 07/11/2023
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and previous versions use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu groff

gnu groff 1.16.1

gnu groff 1.16

gnu groff 1.19.2

gnu groff 1.18.1

gnu groff 1.11a

gnu groff 1.19.1

gnu groff 1.20

gnu groff 1.19

gnu groff 1.20.1

gnu groff 1.14

gnu groff 1.17.2

gnu groff 1.10

gnu groff 1.17.1

gnu groff 1.11

gnu groff 1.15