CVE-2009-5080: Low severity groff vulnerability
The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib/pic2graph/pic2graph.sh scripts in GNU troff (aka groff) 1.21 and earlier do not properly handle certain failed attempts to create temporary directories, which might allow local users to overwrite arbitrary files via a symlink attack on a file in a temporary directory, a different vulnerability than CVE-2004-1296.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-5080?
CVE-2009-5080 has been classified as a local privilege escalation vulnerability.
How do I fix CVE-2009-5080?
To mitigate CVE-2009-5080, it is recommended to upgrade to a version of GNU troff later than 1.21.
Which versions of GNU troff are affected by CVE-2009-5080?
CVE-2009-5080 affects GNU troff version 1.21 and earlier.
Can CVE-2009-5080 be exploited remotely?
No, CVE-2009-5080 can only be exploited locally by authenticated users.
What types of scripts are involved in CVE-2009-5080?
CVE-2009-5080 involves vulnerability in contrib/eqn2graph.sh, contrib/grap2graph.sh, and contrib/pic2graph.sh scripts.