latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Texlive-extra-utils | Debian | 2011.20120322 (including) | 2011.20120322 (including) |
Texlive-bin | Ubuntu | hardy | * |
Texlive-bin | Ubuntu | lucid | * |
Texlive-bin | Ubuntu | natty | * |
Texlive-bin | Ubuntu | oneiric | * |
Texlive-bin | Ubuntu | precise | * |
Texlive-bin | Ubuntu | quantal | * |
Texlive-bin | Ubuntu | raring | * |
Texlive-bin | Ubuntu | saucy | * |
Texlive-bin | Ubuntu | upstream | * |