3.3
CVSSv2

CVE-2013-1444

Published: 30/09/2013 Updated: 11/10/2013
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

A certain Debian patch for txt2man 1.5.5, as used in txt2man 1.5.5-2, 1.5.5-4, and others, allows local users to overwrite arbitrary files via a symlink attack on /tmp/2222.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian txt2man 1.5.5-4

marc vertes txt2man 1.5.5

debian txt2man 1.5.5-2

Vendor Advisories

txt2man could be made to overwrite files ...
Debian Bug report logs - #724614 txt2man: CVE-2013-1444: unsafe use of temporary files Package: txt2man; Maintainer for txt2man is Joao Eriberto Mota Filho <eriberto@debianorg>; Source for txt2man is src:txt2man (PTS, buildd, popcon) Reported by: Jonathan Wiltshire <jmw@debianorg> Date: Wed, 25 Sep 2013 18:54:01 UT ...