---
title: "CVE-2004-0969\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2004-0969?format=md
keywords: index, follow
---

# CVE-2004-0969

Publication date 9 February 2005

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The groffer script in the Groff package 1.18 and later versions, as used in
Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems,
allows local users to overwrite files via a symlink attack on temporary
files.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| groff | 7.04 feisty | Fixed 1.18.1.1-11 |
| 6.10 edgy | Fixed 1.18.1.1-11 |
| 6.06 LTS dapper | Fixed 1.18.1.1-11 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0969)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2004-0969)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2004-0969)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2004-0969)

### Related Ubuntu Security Notices (USN)

+ [USN-13-1](https://usn.ubuntu.com/USN-13-1)
+ groff utility vulnerability
+ 2 November 2004

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2004-0969>
