latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Texlive-extra-utils | Debian | 2011.20120322 (including) | 2011.20120322 (including) |