noweb 2.10c and earlier allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Noweb | Norman_ramsey | 2.9a (including) | 2.9a (including) |
| Noweb | Norman_ramsey | 2.10c (including) | 2.10c (including) |
| Noweb | Ubuntu | dapper | * |
| Noweb | Ubuntu | devel | * |
| Noweb | Ubuntu | edgy | * |
| Noweb | Ubuntu | feisty | * |