GNU Troff pdfroff Insecure Temporary File Creation and Arbitrary File Access Vulnerabilities
BID:36381
Info
GNU Troff pdfroff Insecure Temporary File Creation and Arbitrary File Access Vulnerabilities
| Bugtraq ID: | 36381 |
| Class: | Design Error |
| CVE: |
CVE-2009-5044 CVE-2009-5078 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 24 2009 12:00AM |
| Updated: | Nov 03 2015 07:02PM |
| Credit: | Brian M. Carlson |
| Vulnerable: |
Mandriva Business Server 1 X86 64 Mandriva Business Server 1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 GNU groff 1.19.1 GNU groff 1.19 GNU groff 1.18 GNU groff 1.17.2 GNU groff 1.17 GNU groff 1.16 GNU groff 1.15 GNU groff 1.14 GNU groff 1.11 a GNU groff 1.11 GNU groff 1.10 GNU groff 1.20 Gentoo Linux Apple Mac Os X 10.10.4 Apple Mac Os X 10.10.3 Apple Mac OS X 10.10.2 Apple Mac OS X 10.10.1 Apple Mac OS X 10.10 |
| Not Vulnerable: |
Apple Mac Os X 10.10.5 |
Discussion
GNU Troff pdfroff Insecure Temporary File Creation and Arbitrary File Access Vulnerabilities
GNU Troff (groff) creates temporary files in an insecure manner and allows unauthorized users to modify or delete files.
Successful exploits may allow attackers mount a symlink attack, which may allow the attacker to delete or corrupt sensitive files. Attackers can also rename arbitrary files and potentially cause a denial-of-service condition. Other attacks are also possible.
GNU Troff (groff) creates temporary files in an insecure manner and allows unauthorized users to modify or delete files.
Successful exploits may allow attackers mount a symlink attack, which may allow the attacker to delete or corrupt sensitive files. Attackers can also rename arbitrary files and potentially cause a denial-of-service condition. Other attacks are also possible.
Exploit / POC
GNU Troff pdfroff Insecure Temporary File Creation and Arbitrary File Access Vulnerabilities
An attacker uses readily available commands to launch attacks.
An attacker uses readily available commands to launch attacks.
Solution / Fix
GNU Troff pdfroff Insecure Temporary File Creation and Arbitrary File Access Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
GNU Troff pdfroff Insecure Temporary File Creation and Arbitrary File Access Vulnerabilities
References:
References:
- CVE id request: groff (pdfroff) (Nico Golde)
- GNU Troff (groff) Home Page (GNU)
- groff: pdfroff invokes gs insecurely (without -dSAFER) (Brian M. Carlson)
- groff: pdfroff uses (and documents!) insecure temporary files (Brian M. Carlson)