contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.
CVSS Details
- CVSS 3.1 Base Score: 4.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2015-006 | Aug 28, 2015 | Jun 24, 2011 |
| Apple Osx Groff | — | Upgrade macOS to the latest version | Mar 29, 2016 | Jun 24, 2011 |
| Debian | — | Upgrade groff | Jul 30, 2024 | Jun 24, 2011 |
| Gentoo Linux | — | Upgrade sys-apps/groff. | Oct 30, 2017 | Jun 24, 2011 |
| Suse | — | Upgrade gxditviewUpgrade groff-docUpgrade soelim-commonUpgrade groffUpgrade groff-full | Dec 12, 2013 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub