CVE-2009-5078: Medium severity groff vulnerability
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-5078?
CVE-2009-5078 is categorized as a high-severity vulnerability due to its potential to allow unauthorized file manipulation.
How do I fix CVE-2009-5078?
To fix CVE-2009-5078, upgrade to GNU troff version 1.21 or later, which includes the necessary changes to prevent this vulnerability.
What systems are affected by CVE-2009-5078?
CVE-2009-5078 affects all versions of GNU troff prior to 1.21 and certain versions of macOS operating systems.
What type of attack is CVE-2009-5078 associated with?
CVE-2009-5078 is associated with remote code execution attacks that exploit improper handling of Ghostscript commands.
Is CVE-2009-5078 still a risk in modern environments?
Yes, CVE-2009-5078 remains a risk in environments that use vulnerable versions of GNU troff, especially if exposed to untrusted documents.