Upstream information

CVE-2009-5080 at MITRE

Description

The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib/pic2graph/pic2graph.sh scripts in GNU troff (aka groff) 1.21 and earlier do not properly handle certain failed attempts to create temporary directories, which might allow local users to overwrite arbitrary files via a symlink attack on a file in a temporary directory, a different vulnerability than CVE-2004-1296.

SUSE information

Overall state of this security issue: Ignore

This issue is currently rated as having low severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 3.3
Vector AV:L/AC:M/Au:N/C:N/I:P/A:P
Access Vector Local
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact Partial
SUSE Bugzilla entry: 703665 [RESOLVED / FIXED]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 12
  • groff >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Desktop 12 GA groff
SUSE Linux Enterprise Desktop 12 SP1
  • groff >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Desktop 12 SP1 GA groff
SUSE Linux Enterprise Desktop 12 SP2
  • groff >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Desktop 12 SP2 GA groff
SUSE Linux Enterprise Desktop 12 SP3
  • groff >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Desktop 12 SP3 GA groff
SUSE Linux Enterprise Module for Basesystem 15
  • groff >= 1.22.3-3.12
  • groff-full >= 1.22.3-3.24
  • gxditview >= 1.22.3-3.24
Patchnames:
SUSE Linux Enterprise Module for Basesystem 15 GA groff
SUSE Linux Enterprise Server 12
  • groff >= 1.22.2-5.429
  • groff-full >= 1.22.2-5.429
  • gxditview >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Server 12 GA groff
SUSE Linux Enterprise Server 12 SP1
  • groff >= 1.22.2-5.429
  • groff-full >= 1.22.2-5.429
  • gxditview >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Server 12 SP1 GA groff
SUSE Linux Enterprise Server 12 SP2
  • groff >= 1.22.2-5.429
  • groff-full >= 1.22.2-5.429
  • gxditview >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Server 12 SP2 GA groff
SUSE Linux Enterprise Server 12 SP3
  • groff >= 1.22.2-5.429
  • groff-full >= 1.22.2-5.429
  • gxditview >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Server 12 SP3 GA groff
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
  • groff >= 1.22.2-5.287
  • groff-full >= 1.22.2-5.287
  • gxditview >= 1.22.2-5.287
Patchnames:
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 GA groff
openSUSE Leap 15.0
  • groff >= 1.22.3-lp150.3.1
  • groff-full >= 1.22.3-lp150.3.14
  • gxditview >= 1.22.3-lp150.3.14
Patchnames:
openSUSE Leap 15.0 GA groff
openSUSE Leap 42.1
  • groff >= 1.22.2-7.4
  • groff-full >= 1.22.2-7.7
  • gxditview >= 1.22.2-7.7
Patchnames:
openSUSE Leap 42.1 GA groff
openSUSE Leap 42.2
  • groff >= 1.22.2-8.17
  • groff-full >= 1.22.2-8.35
  • gxditview >= 1.22.2-8.35
Patchnames:
openSUSE Leap 42.2 GA groff
openSUSE Leap 42.3
  • groff >= 1.22.2-10.5
  • groff-full >= 1.22.2-10.22
  • gxditview >= 1.22.2-10.22
Patchnames:
openSUSE Leap 42.3 GA groff
openSUSE Tumbleweed
  • groff >= 1.22.3-2.5
  • groff-doc >= 1.22.3-2.5
  • groff-full >= 1.22.3-2.5
  • gxditview >= 1.22.3-2.5
Patchnames:
openSUSE Tumbleweed GA groff