Description
The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2892-1 | a2ps security update |
EUVD |
EUVD-2001-1570 | The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T04:58:11.469Z
Reserved: 2014-02-05T00:00:00.000Z
Link: CVE-2001-1593
No data.
Status : Modified
Published: 2014-04-05T21:55:06.097
Modified: 2026-05-06T22:30:45.220
Link: CVE-2001-1593
OpenCVE Enrichment
No data.
Debian DSA
EUVD