The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier,...
Vulnerability Description
The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2001-1593
Credits & Attribution
No credits recorded in the NVD database.
References
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737385
- http://pkgs.fedoraproject.org/cgit/a2ps.git/plain/a2ps-4.13-security.patch
- https://bugzilla.redhat.com/show_bug.cgi?id=1060630
- http://seclists.org/oss-sec/2014/q1/253
- http://seclists.org/oss-sec/2014/q1/257
- http://www.debian.org/security/2014/dsa-2892
- http://seclists.org/oss-sec/2014/q1/237
More from gnu
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.