USN-13-1: groff utility vulnerability
2 November 2004
groff utility vulnerability
Releases
Details
Recently, Trustix Secure Linux discovered a vulnerability in the groff
package. The utility "groffer" created a temporary directory in an
insecure way, which allowed exploitation of a race condition to create
or overwrite files with the privileges of the user invoking the
program.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 4.10
-
groff
-
In general, a standard system update will make all the necessary changes.