MEDIUM
xfig: insecure use of temporary files
Published Jun 6, 2009
4.4
MEDIUMCVSS 2.0
EPSS 0.33%
Description
Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or (11) xfig-spell.[PID] temporary files, where [PID] is a process ID.
Affected products
No data.
OR
- 3.2.5
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
No data.
Red Hat Enterprise Linux 4
xfig
Will not fix
Red Hat Enterprise Linux 5
xfig
Will not fix
Red Hat Enterprise Linux 6
xfig
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | xfig | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | xfig | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | xfig | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://secunia.com/advisories/35320 third-party-advisoryx_refsource_SECUNIA
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:244 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2009/04/01/6 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/34328 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2009-1962 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=505257 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49600 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-1962
- https://www.cve.org/CVERecord?id=CVE-2009-1962
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/35320 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2009:244 | vendor-advisoryx_refsource_MANDRIVA | |
| http://www.openwall.com/lists/oss-security/2009/04/01/6 | mailing-listx_refsource_MLIST | |
| http://www.securityfocus.com/bid/34328 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2009-1962 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=505257 | Issue Tracking | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/49600 | vdb-entryx_refsource_XF | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-1962 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-1962 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 6, 2009
Updated Aug 7, 2024
Reserved Jun 6, 2009
Link CVE-2009-1962
CISA Vulnrichment
Updated n/a