USN-43-1: groff utility vulnerabilities
21 December 2004
groff utility vulnerabilities
Releases
Details
Javier Fernández-Sanguino Peña discovered that the auxiliary scripts
"eqn2graph" and "pic2graph" created temporary files in an insecure
way, which allowed exploitation of a race condition to create or
overwrite files with the privileges of the user invoking the program.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 4.10
-
groff
-
In general, a standard system update will make all the necessary changes.