All errata/sisyphus/ALT-PU-2016-1079-1
ALT-PU-2016-1079-1

Package update groff in branch sisyphus

Version1.22.3-alt1
Published2016-02-04
Max severityMEDIUM
Severity:

Closed issues (6)

CVE-2009-5044
LOW3.3

contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.

Published: 2011-06-24Modified: 2026-04-29
CVSS 2.0LOW 3.3
CVSS:2.0/AV:L/AC:M/Au:N/C:N/I:P/A:P
References
CVE-2009-5081
LOW3.3

The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969.

Published: 2011-06-30Modified: 2026-04-29
CVSS 2.0LOW 3.3
CVSS:2.0/AV:L/AC:M/Au:N/C:N/I:P/A:P