CVE-2009-5081
Estado: ModificadaBaja (3.3)—
The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P
- Puntuación base: 3.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.29%
- Percentil entre todas las CVEs puntuadas: 20
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-59
Referencias
- http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diff
- http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diff.diff?r1=1.1%3Br2=1.2%3Bf=h
- http://openwall.com/lists/oss-security/2009/08/14/4
- http://openwall.com/lists/oss-security/2009/08/14/5
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:086
- http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diff
- http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diff.diff?r1=1.1%3Br2=1.2%3Bf=h
- http://openwall.com/lists/oss-security/2009/08/14/4
- http://openwall.com/lists/oss-security/2009/08/14/5
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:086
JSON original (NVD)
Mostrar
{
"id": "CVE-2009-5081",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.3,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:N/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2011-06-30T15:55:01.770",
"references": [
{
"url": "http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diff",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diff.diff?r1=1.1%3Br2=1.2%3Bf=h",
"source": "cve@mitre.org"
},
{
"url": "http://openwall.com/lists/oss-security/2009/08/14/4",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://openwall.com/lists/oss-security/2009/08/14/5",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2013:086",
"source": "cve@mitre.org"
},
{
"url": "http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diff",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/groff/groff-1.20.1-owl-tmp.diff.diff?r1=1.1%3Br2=1.2%3Bf=h",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://openwall.com/lists/oss-security/2009/08/14/4",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://openwall.com/lists/oss-security/2009/08/14/5",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2013:086",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-59"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969."
},
{
"lang": "es",
"value": "Los scripts (1) config.guess ,(2) contrib / groffer / perl / groffer.pl, y (3) contrib/groffer/perl/roff2.pl en GNU troff (también conocido como groff) v1.21 y anteriores, utilizan un número insuficiente de X caracteres en el argumento plantilla (template) en la función tempfile, lo que hace más fácil para los usuarios locales sobreescribir ficheros arbitrarios mediante un ataque de enlaces simbólicos en un archivo temporal, una vulnerabilidad diferente a CVE-2004-0969."
}
],
"lastModified": "2026-06-16T23:14:57.457",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gnu:groff:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "66EE516B-88DB-47BC-AC1D-66B7C8E39AB1",
"versionEndIncluding": "1.21"
},
{
"criteria": "cpe:2.3:a:gnu:groff:1.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35017C15-4CCD-4B44-9108-F5650319A009"
},
{
"criteria": "cpe:2.3:a:gnu:groff:1.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B8AC4613-F1BE-4EEE-84C3-A13D2AC048B8"
},
{
"criteria": "cpe:2.3:a:gnu:groff:1.11a:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D6BD17C-0DE9-405D-BC02-E996FBC4F97A"
},
{
"criteria": "cpe:2.3:a:gnu:groff:1.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5493392A-B8E1-4F71-A1ED-6889FD1CC217"
},
{
"criteria": "cpe:2.3:a:gnu:groff:1.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BDF86410-1841-4549-A0FE-3D16C6CCE383"
},
{
"criteria": "cpe:2.3:a:gnu:groff:1.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C91EE2C2-DE96-494D-BEEE-D07ED74EDEAC"
},
{
"criteria": "cpe:2.3:a:gnu:groff:1.16.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EDB1389A-0F7D-4616-8553-AF1E40B05256"
},
{
"criteria": "cpe:2.3:a:gnu:groff:1.17.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6D4A1AC6-2820-4992-B652-EF6FD308D643"
},
{
"criteria": "cpe:2.3:a:gnu:groff:1.17.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59A32AD0-B019-4FAF-BC8A-01FE6F90628E"
},
{
"criteria": "cpe:2.3:a:gnu:groff:1.18.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A81CEA14-F694-431F-BAC9-BBB8CC09BBCB"
},
{
"criteria": "cpe:2.3:a:gnu:groff:1.19:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3C3A17D1-F3A9-45FC-A943-C47B8121599C"
},
{
"criteria": "cpe:2.3:a:gnu:groff:1.19.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0D64601D-0EA0-40AD-9E25-74360051CC2C"
},
{
"criteria": "cpe:2.3:a:gnu:groff:1.19.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D944298-B544-4D38-96A3-5CA22C9C3C7B"
},
{
"criteria": "cpe:2.3:a:gnu:groff:1.20:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F737E42-B8F1-4C9C-B3E9-382BCE43859D"
},
{
"criteria": "cpe:2.3:a:gnu:groff:1.20.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9ECE4B65-2CE6-44B6-B29E-97ECA0014C1D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}