CVE-2001-1593

The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnu:a2ps:*:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.10.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.10.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.12:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.13:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.13b:*:*:*:*:*:*:*

History

20 Nov 2024, 23:38

Type Values Removed Values Added
References () http://pkgs.fedoraproject.org/cgit/a2ps.git/plain/a2ps-4.13-security.patch - () http://pkgs.fedoraproject.org/cgit/a2ps.git/plain/a2ps-4.13-security.patch -
References () http://seclists.org/oss-sec/2014/q1/237 - () http://seclists.org/oss-sec/2014/q1/237 -
References () http://seclists.org/oss-sec/2014/q1/253 - () http://seclists.org/oss-sec/2014/q1/253 -
References () http://seclists.org/oss-sec/2014/q1/257 - () http://seclists.org/oss-sec/2014/q1/257 -
References () http://www.debian.org/security/2014/dsa-2892 - () http://www.debian.org/security/2014/dsa-2892 -
References () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737385 - () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737385 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=1060630 - () https://bugzilla.redhat.com/show_bug.cgi?id=1060630 -

Information

Published : 2014-04-05 21:55

Updated : 2024-11-20 23:38


NVD link : CVE-2001-1593

Mitre link : CVE-2001-1593

CVE.ORG link : CVE-2001-1593


JSON object : View

Products Affected

gnu

  • a2ps
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')