CVE Vulnerabilities

CVE-2012-2120

Published: May 18, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.3 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

Affected Software

NameVendorStart VersionEnd Version
Texlive-extra-utilsDebian2011.20120322 (including)2011.20120322 (including)
Texlive-binUbuntuhardy*
Texlive-binUbuntulucid*
Texlive-binUbuntunatty*
Texlive-binUbuntuoneiric*
Texlive-binUbuntuprecise*
Texlive-binUbuntuquantal*
Texlive-binUbunturaring*
Texlive-binUbuntusaucy*
Texlive-binUbuntuupstream*

References