|
GNU Troff (Groff) Groffer Script Insecure Temporary File Creation Vulnerability
GNU Troff ('groff') creates temporary files in an insecure manner. This issue is due to a design error that causes the application to fail to verify the presence of a file before writing to it. An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly, this issue is unlikely to facilitate privilege escalation. |
|
|
Privacy Statement |