CVE-2004-1296: Low severity GNU groff vulnerability
Published Dec 31, 2004
·Updated
The (1) eqn2graph and (2) pic2graph scripts in groff 1.18.1 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
Affected Software
2 affected components
GNU groff=1.18.1
GNU groff=1.18.1
Event History
Dec 31, 2004
CVE Published
05:00 AM
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1296?
CVE-2004-1296 has been classified as a medium severity vulnerability due to its potential for file overwriting via a symlink attack.
2
How do I fix CVE-2004-1296?
To fix CVE-2004-1296, it is recommended to update to a version of groff that is not affected by this vulnerability.
3
What versions of groff are affected by CVE-2004-1296?
CVE-2004-1296 specifically affects groff version 1.18.1.
4
What types of attacks can CVE-2004-1296 facilitate?
CVE-2004-1296 facilitates local file overwriting attacks through symlink manipulation.
5
Is CVE-2004-1296 a remote or local vulnerability?
CVE-2004-1296 is a local vulnerability that requires an authenticated user to exploit.