CVE-2012-2120: Low severity tex live vulnerability
latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2120?
CVE-2012-2120 is considered a medium-severity vulnerability due to its potential for local users to exploit file overwrite circumstances.
How do I fix CVE-2012-2120?
To fix CVE-2012-2120, update the texlive-extra-utils package to a version that does not allow symlink attacks on temporary files.
Who is affected by CVE-2012-2120?
CVE-2012-2120 affects users running the texlive-extra-utils version 2011.20120322 or potentially other vulnerable versions.
What are the implications of CVE-2012-2120?
The implications of CVE-2012-2120 include the risk of local users overwriting arbitrary files, which can lead to unauthorized access or data loss.
Is CVE-2012-2120 a remote or local vulnerability?
CVE-2012-2120 is a local vulnerability that requires authenticated access to the system to exploit.