A certain Debian patch for txt2man 1.5.5, as used in txt2man 1.5.5-2, 1.5.5-4, and others, allows local users to overwrite arbitrary files via a symlink attack on /tmp/2222.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=724614 - | |
References | () http://osvdb.org/97769 - | |
References | () http://seclists.org/oss-sec/2013/q3/660 - | |
References | () http://www.ubuntu.com/usn/USN-1979-1 - |
Information
Published : 2013-09-30 22:55
Updated : 2024-11-21 01:49
NVD link : CVE-2013-1444
Mitre link : CVE-2013-1444
CVE.ORG link : CVE-2013-1444
JSON object : View
Products Affected
debian
- txt2man
marc_vertes
- txt2man
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')