Upstream information

CVE-2009-5081 at MITRE

Description

The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969.

SUSE information

Overall state of this security issue: Ignore

This issue is currently rated as having low severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 3.3
Vector AV:L/AC:M/Au:N/C:N/I:P/A:P
Access Vector Local
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact Partial
SUSE Bugzilla entry: 703666 [RESOLVED / FIXED]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 12
  • groff >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Desktop 12 GA groff
SUSE Linux Enterprise Desktop 12 SP1
  • groff >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Desktop 12 SP1 GA groff
SUSE Linux Enterprise Desktop 12 SP2
  • groff >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Desktop 12 SP2 GA groff
SUSE Linux Enterprise Desktop 12 SP3
  • groff >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Desktop 12 SP3 GA groff
SUSE Linux Enterprise Module for Basesystem 15
  • groff >= 1.22.3-3.12
  • groff-full >= 1.22.3-3.24
  • gxditview >= 1.22.3-3.24
Patchnames:
SUSE Linux Enterprise Module for Basesystem 15 GA groff
SUSE Linux Enterprise Server 12
  • groff >= 1.22.2-5.429
  • groff-full >= 1.22.2-5.429
  • gxditview >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Server 12 GA groff
SUSE Linux Enterprise Server 12 SP1
  • groff >= 1.22.2-5.429
  • groff-full >= 1.22.2-5.429
  • gxditview >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Server 12 SP1 GA groff
SUSE Linux Enterprise Server 12 SP2
  • groff >= 1.22.2-5.429
  • groff-full >= 1.22.2-5.429
  • gxditview >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Server 12 SP2 GA groff
SUSE Linux Enterprise Server 12 SP3
  • groff >= 1.22.2-5.429
  • groff-full >= 1.22.2-5.429
  • gxditview >= 1.22.2-5.429
Patchnames:
SUSE Linux Enterprise Server 12 SP3 GA groff
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
  • groff >= 1.22.2-5.287
  • groff-full >= 1.22.2-5.287
  • gxditview >= 1.22.2-5.287
Patchnames:
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 GA groff
openSUSE Leap 15.0
  • groff >= 1.22.3-lp150.3.1
  • groff-full >= 1.22.3-lp150.3.14
  • gxditview >= 1.22.3-lp150.3.14
Patchnames:
openSUSE Leap 15.0 GA groff
openSUSE Leap 42.1
  • groff >= 1.22.2-7.4
  • groff-full >= 1.22.2-7.7
  • gxditview >= 1.22.2-7.7
Patchnames:
openSUSE Leap 42.1 GA groff
openSUSE Leap 42.2
  • groff >= 1.22.2-8.17
  • groff-full >= 1.22.2-8.35
  • gxditview >= 1.22.2-8.35
Patchnames:
openSUSE Leap 42.2 GA groff
openSUSE Leap 42.3
  • groff >= 1.22.2-10.5
  • groff-full >= 1.22.2-10.22
  • gxditview >= 1.22.2-10.22
Patchnames:
openSUSE Leap 42.3 GA groff
openSUSE Tumbleweed
  • groff >= 1.22.3-2.5
  • groff-doc >= 1.22.3-2.5
  • groff-full >= 1.22.3-2.5
  • gxditview >= 1.22.3-2.5
Patchnames:
openSUSE Tumbleweed GA groff