latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2012-05-18T22:00:00Z

Updated: 2024-09-16T16:28:56.219Z

Reserved: 2012-04-04T00:00:00Z

Link: CVE-2012-2120

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2012-05-18T22:55:03.247

Modified: 2012-05-21T16:24:56.587

Link: CVE-2012-2120

cve-icon Redhat

No data.