CVE-2009-5082: Low severity groff vulnerability
The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU//Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-5082?
CVE-2009-5082 is considered a moderate severity vulnerability due to its potential for local user exploitation via a symlink attack.
How do I fix CVE-2009-5082?
To fix CVE-2009-5082, ensure you update to a patched version of GNU troff later than 1.20.1 that mitigates the symlink vulnerability.
What systems are affected by CVE-2009-5082?
CVE-2009-5082 affects GNU troff version 1.20.1 when deployed on Openwall GNU/*/Linux systems.
What type of attack does CVE-2009-5082 enable?
CVE-2009-5082 enables a local symlink attack, allowing users to overwrite arbitrary files.
Who can exploit CVE-2009-5082?
Any local user with access to the system running the affected version of GNU troff can exploit CVE-2009-5082.