CVE-2012-2120

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
18/05/2012
Last modified:
11/04/2025

Description

latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:debian:texlive-extra-utils:2011.20120322:*:*:*:*:*:*:*