CVE Vulnerabilities

CVE-2009-5078

Published: Jun 30, 2011 | Modified: Apr 11, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
1.9 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.

Affected Software

NameVendorStart VersionEnd Version
GroffGnu*1.20.1 (including)
GroffGnu1.10 (including)1.10 (including)
GroffGnu1.11 (including)1.11 (including)
GroffGnu1.11a (including)1.11a (including)
GroffGnu1.14 (including)1.14 (including)
GroffGnu1.15 (including)1.15 (including)
GroffGnu1.16 (including)1.16 (including)
GroffGnu1.16.1 (including)1.16.1 (including)
GroffGnu1.17.1 (including)1.17.1 (including)
GroffGnu1.17.2 (including)1.17.2 (including)
GroffGnu1.18.1 (including)1.18.1 (including)
GroffGnu1.19 (including)1.19 (including)
GroffGnu1.19.1 (including)1.19.1 (including)
GroffGnu1.19.2 (including)1.19.2 (including)
GroffGnu1.20 (including)1.20 (including)
GroffUbuntuupstream*

References