CVE-2013-1444: Low severity Debian txt2man vulnerability
Published Sep 30, 2013
·Updated
A certain Debian patch for txt2man 1.5.5, as used in txt2man 1.5.5-2, 1.5.5-4, and others, allows local users to overwrite arbitrary files via a symlink attack on /tmp/2222.
Affected Software
3 affected components
Debian txt2man=1.5.5-2
Debian txt2man=1.5.5-4
Marc Vertes Txt2man=1.5.5
Event History
Sep 30, 2013
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1444?
CVE-2013-1444 has a moderate severity as it allows local users to perform a symlink attack that can overwrite arbitrary files.
2
How do I fix CVE-2013-1444?
To fix CVE-2013-1444, update the affected txt2man versions to a patched version that mitigates the symlink vulnerability.
3
Which software versions are affected by CVE-2013-1444?
CVE-2013-1444 affects txt2man versions 1.5.5-2 and 1.5.5-4 from Debian, as well as any version of txt2man 1.5.5 from Marc Vertes.
4
Can CVE-2013-1444 be exploited remotely?
No, CVE-2013-1444 can only be exploited locally by users with access to the system.
5
What impact does CVE-2013-1444 have on system security?
CVE-2013-1444 can lead to unauthorized file modifications, potentially compromising the integrity of the system.