CVE Vulnerabilities

CVE-2012-2120

Published: May 18, 2012 | Modified: May 21, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.3 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE

latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

Affected Software

Name Vendor Start Version End Version
Texlive-extra-utils Debian 2011.20120322 (including) 2011.20120322 (including)
Texlive-bin Ubuntu hardy *
Texlive-bin Ubuntu lucid *
Texlive-bin Ubuntu natty *
Texlive-bin Ubuntu oneiric *
Texlive-bin Ubuntu precise *
Texlive-bin Ubuntu quantal *
Texlive-bin Ubuntu raring *
Texlive-bin Ubuntu saucy *
Texlive-bin Ubuntu upstream *

References