contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Groff | Gnu | * | 1.20.1 (including) |
Groff | Gnu | 1.10 (including) | 1.10 (including) |
Groff | Gnu | 1.11 (including) | 1.11 (including) |
Groff | Gnu | 1.11a (including) | 1.11a (including) |
Groff | Gnu | 1.14 (including) | 1.14 (including) |
Groff | Gnu | 1.15 (including) | 1.15 (including) |
Groff | Gnu | 1.16 (including) | 1.16 (including) |
Groff | Gnu | 1.16.1 (including) | 1.16.1 (including) |
Groff | Gnu | 1.17.1 (including) | 1.17.1 (including) |
Groff | Gnu | 1.17.2 (including) | 1.17.2 (including) |
Groff | Gnu | 1.18.1 (including) | 1.18.1 (including) |
Groff | Gnu | 1.19 (including) | 1.19 (including) |
Groff | Gnu | 1.19.1 (including) | 1.19.1 (including) |
Groff | Gnu | 1.19.2 (including) | 1.19.2 (including) |
Groff | Gnu | 1.20 (including) | 1.20 (including) |
Groff | Ubuntu | upstream | * |