The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
2004-12-27T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 2.1 (LOW)
AV:L/AC:L/Au:N/C:N/I:P/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnu | a2ps | 4.13 | Yes |
Application | gnu | a2ps | 4.13b | Yes |
Operating System | turbolinux | turbolinux_home | * | Yes |
Operating System | turbolinux | turbolinux_server | 7.0 | Yes |
Operating System | turbolinux | turbolinux_server | 8.0 | Yes |
Operating System | turbolinux | turbolinux_workstation | 7.0 | Yes |
Operating System | turbolinux | turbolinux_workstation | 8.0 | Yes |