CVE-2001-1593

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
05/04/2014
Last modified:
12/04/2025

Description

The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:a2ps:*:*:*:*:*:*:*:* 4.14 (including)
cpe:2.3:a:gnu:a2ps:4.10.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.10.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.12:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.13:*:*:*:*:*:*:*
cpe:2.3:a:gnu:a2ps:4.13b:*:*:*:*:*:*:*