CVE detail
CVE-2009-5081 — CVE-2009-5081
Published 2011-06-30 · Modified 2026-06-16 · Vendor gnu · Product groff · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0029
EPSS probability
exploitation probability, 30d
22.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References