Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib/pic2graph/pic2graph.sh scripts in GNU troff (aka groff) 1.21 and earlier do not properly handle certain failed attempts to create temporary directories, which might allow local users to overwrite arbitrary files via a symlink attack on a file in a temporary directory, a different vulnerability than CVE-2004-1296.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GNU troff后置链接漏洞
Vulnerability Description
Groff (GNU Troff) 是Troff 的最新开放源码实现,Troff是从相同的输入源为各种设备生成打印和屏幕文档的一种文档准备系统。 GNU troff(groff)1.21及早期版本的contrib/eqn2graph/eqn2graph.sh,contrib/grap2graph/grap2graph.sh和contrib/pic2graph/pic2graph.sh脚本程序不能对某些没有成功创建临时目录的尝试进行正确处理。本地用户可借助临时目录内文件上的符号链接攻击重写任意文件。
CVSS Information
N/A
Vulnerability Type
N/A