CVE-2009-5080

EUVD-2009-5035
The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib/pic2graph/pic2graph.sh scripts in GNU troff (aka groff) 1.21 and earlier do not properly handle certain failed attempts to create temporary directories, which might allow local users to overwrite arbitrary files via a symlink attack on a file in a temporary directory, a different vulnerability than CVE-2004-1296.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:N/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
Affected Products (NVD)
VendorProductVersion
gnugroff
𝑥
≤ 1.21
gnugroff
1.10
gnugroff
1.11
gnugroff
1.11a:a
gnugroff
1.14
gnugroff
1.15
gnugroff
1.16
gnugroff
1.16.1
gnugroff
1.17.1
gnugroff
1.17.2
gnugroff
1.18.1
gnugroff
1.19
gnugroff
1.19.1
gnugroff
1.19.2
gnugroff
1.20
gnugroff
1.20.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
groff
bookworm
1.22.4-10
fixed
bullseye
1.22.4-6
fixed
lenny
no-dsa
sid
1.23.0-5
fixed
trixie
1.23.0-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
groff
artful
ignored
bionic
needed
cosmic
ignored
disco
ignored
eoan
ignored
focal
not-affected
groovy
ignored
hardy
ignored
hirsute
ignored
impish
ignored
jammy
not-affected
kinetic
not-affected
lucid
ignored
lunar
not-affected
mantic
not-affected
maverick
ignored
natty
ignored
noble
not-affected
oneiric
ignored
precise
ignored
quantal
ignored
raring
ignored
saucy
ignored
trusty
needed
utopic
ignored
vivid
ignored
wily
ignored
xenial
needed
yakkety
ignored
zesty
ignored