VulnerabilityModified
CVE-2012-2120
latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
LOW 3.3EPSS 0.31%
Does this matter?
Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.
Description
latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
- CVSS 2.0
- 3.3 LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
- EPSS
- 0.31% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- debian/texlive-extra-utils
- Source
- secalert@redhat.com
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=668779
- http://www.openwall.com/lists/oss-security/2012/04/19/12
- http://www.openwall.com/lists/oss-security/2012/04/19/15
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=668779
- http://www.openwall.com/lists/oss-security/2012/04/19/12
- http://www.openwall.com/lists/oss-security/2012/04/19/15
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.