CVE-2013-1444

Publication date 25 September 2013

Last updated 24 July 2024


Ubuntu priority

A certain Debian patch for txt2man 1.5.5, as used in txt2man 1.5.5-2, 1.5.5-4, and others, allows local users to overwrite arbitrary files via a symlink attack on /tmp/2222.

Read the notes from the security team

Status

Package Ubuntu Release Status
txt2man 13.04 raring
Fixed 1.5.5-4ubuntu0.13.04.1
12.10 quantal
Fixed 1.5.5-4ubuntu0.12.10.1
12.04 LTS precise
Fixed 1.5.5-4ubuntu0.12.04.1
10.04 LTS lucid Ignored end of life

Notes


seth-arnold

"echo $post > /tmp/2222" -- looks like unsafe quoting, too.

References

Related Ubuntu Security Notices (USN)

    • USN-1979-1
    • txt2man vulnerability
    • 30 September 2013

Other references