noweb 2.10c and earlier allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Noweb | Norman_ramsey | 2.9a (including) | 2.9a (including) |
Noweb | Norman_ramsey | 2.10c (including) | 2.10c (including) |
Noweb | Ubuntu | dapper | * |
Noweb | Ubuntu | devel | * |
Noweb | Ubuntu | edgy | * |
Noweb | Ubuntu | feisty | * |