CVE-2001-1593

The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnu:a2ps:4.10.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:*:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.13b:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.13:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.10.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.12:*:*:*:*:*:*:*

Information

Published : 2014-04-05 14:55

Updated : 2014-04-30 18:20


NVD link : CVE-2001-1593

Mitre link : CVE-2001-1593


JSON object : View

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')

Advertisement

dedicated server usa

Products Affected

gnu

  • a2ps