VulnerabilityModified
CVE-2007-5936
dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain temporary files before they are processed by dviljk, which can then be read or modified in place.
LOW 3.6EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain temporary files before they are processed by dviljk, which can then be read or modified in place.
- CVSS 2.0
- 3.6 LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- tetex/tetex · tug/texlive 2007
- Source
- cve@mitre.org
References
- http://bugs.gentoo.org/attachment.cgi?id=135423
- http://bugs.gentoo.org/show_bug.cgi?id=198238
- http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.html
- http://osvdb.org/42238
- http://secunia.com/advisories/27672Vendor Advisory
- http://secunia.com/advisories/27686Vendor Advisory
- http://secunia.com/advisories/27718Vendor Advisory
- http://secunia.com/advisories/27743Vendor Advisory
- http://secunia.com/advisories/27967Vendor Advisory
- http://secunia.com/advisories/28107Vendor Advisory
- http://secunia.com/advisories/28412Vendor Advisory
- http://secunia.com/advisories/30168Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200711-26.xml
- http://security.gentoo.org/glsa/glsa-200711-34.xml
- http://security.gentoo.org/glsa/glsa-200805-13.xml
- http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0266
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:230
- http://www.securityfocus.com/archive/1/487984/100/0/threaded
- http://www.securityfocus.com/bid/26469
- http://www.securitytracker.com/id?1019058
- http://www.vupen.com/english/advisories/2007/3896
- https://bugzilla.redhat.com/show_bug.cgi?id=368611
- https://issues.rpath.com/browse/RPL-1928
- https://usn.ubuntu.com/554-1/
- https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00663.html
- http://bugs.gentoo.org/attachment.cgi?id=135423
- http://bugs.gentoo.org/show_bug.cgi?id=198238
- http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.