CVE-2012-2120 Information

Description

latex2man in texlive-extra-utils 2011.20120322 and possibly other versions or packages when used with the H or T option allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

Reference

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=668779 http://www.openwall.com/lists/oss-security/2012/04/19/12 http://www.openwall.com/lists/oss-security/2012/04/19/15

Share on: