CVE-2001-1593

The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnu:a2ps:*:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.10.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.10.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.12:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.13:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.13b:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-04-05 21:55

Updated : 2023-12-10 11:31


NVD link : CVE-2001-1593

Mitre link : CVE-2001-1593

CVE.ORG link : CVE-2001-1593


JSON object : View

Products Affected

gnu

  • a2ps
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')