CVE-2001-0906: Medium severity tetex tetex vulnerability
Published Jun 22, 2001
·Updated
teTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produced when printing .dvi files using lpr.
Affected Software
1 affected component
teTeX teTeX<=1.0.7.7
Remediation
Patch Available
Patch Available
Event History
Jun 22, 2001
CVE Published
04:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0906?
CVE-2001-0906 is considered a high-severity vulnerability due to its potential to allow local users to gain elevated privileges.
2
How do I fix CVE-2001-0906?
To fix CVE-2001-0906, you should upgrade to teTeX version 1.0.7.8 or later.
3
What type of attack does CVE-2001-0906 enable?
CVE-2001-0906 enables a symlink attack on temporary files during the printing of .dvi files.
4
Which versions of teTeX are affected by CVE-2001-0906?
Versions of teTeX prior to 1.0.7.8 are affected by CVE-2001-0906.
5
Who is vulnerable to CVE-2001-0906?
Local users on systems running vulnerable versions of teTeX can exploit CVE-2001-0906 to gain privileges.