CVE-2001-1593
Severity CVSS v4.0:
Pending analysis
Type:
CWE-59
Link Following
Publication date:
05/04/2014
Last modified:
12/04/2025
Description
The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.
Impact
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:gnu:a2ps:*:*:*:*:*:*:*:* | 4.14 (including) | |
| cpe:2.3:a:gnu:a2ps:4.10.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:a2ps:4.10.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:a2ps:4.12:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:a2ps:4.13:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:a2ps:4.13b:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://pkgs.fedoraproject.org/cgit/a2ps.git/plain/a2ps-4.13-security.patch
- http://seclists.org/oss-sec/2014/q1/237
- http://seclists.org/oss-sec/2014/q1/253
- http://seclists.org/oss-sec/2014/q1/257
- http://www.debian.org/security/2014/dsa-2892
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737385
- https://bugzilla.redhat.com/show_bug.cgi?id=1060630
- http://pkgs.fedoraproject.org/cgit/a2ps.git/plain/a2ps-4.13-security.patch
- http://seclists.org/oss-sec/2014/q1/237
- http://seclists.org/oss-sec/2014/q1/253
- http://seclists.org/oss-sec/2014/q1/257
- http://www.debian.org/security/2014/dsa-2892
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737385
- https://bugzilla.redhat.com/show_bug.cgi?id=1060630



