CVE-2007-5940: Medium severity Tug Texlive 2007 vulnerability
Published Nov 13, 2007
·Updated
feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the feynmf$$.pl temporary file.
Affected Software
1 affected component
Tug Texlive 2007
Event History
Nov 13, 2007
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5940?
CVE-2007-5940 is considered a medium severity vulnerability due to its potential for local users to execute arbitrary code.
2
How do I fix CVE-2007-5940?
To fix CVE-2007-5940, you should update to a newer version of feynmf that does not allow symlink attacks.
3
Who is affected by CVE-2007-5940?
CVE-2007-5940 affects local users of feynmf 1.08 as used in TeX Live 2007.
4
What kind of attack is involved in CVE-2007-5940?
CVE-2007-5940 involves a symlink attack that allows overwriting arbitrary files.
5
Can CVE-2007-5940 lead to system compromise?
Yes, CVE-2007-5940 can lead to system compromise by enabling local users to execute arbitrary code.