CVE-2013-1444

txt2man 1.5.5-2 1.5.5-4 - Arbitrary File Overwrite via Symlink Attack

Title source: llm
STIX 2.1

Description

A certain Debian patch for txt2man 1.5.5, as used in txt2man 1.5.5-2, 1.5.5-4, and others, allows local users to overwrite arbitrary files via a symlink attack on /tmp/2222.

References (4)

Core 4
Core References
Issue Tracking x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=724614
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/97769
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2013/q3/660
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1979-1

Scores

EPSS 0.0034
EPSS Percentile 25.7%

Details

CWE
CWE-59
Status published
Products (3)
debian/txt2man 1.5.5-2
debian/txt2man 1.5.5-4
marc_vertes/txt2man 1.5.5
Published Sep 30, 2013
Tracked Since Feb 18, 2026