The tempname_ensure function in lib/routines.h in a2ps 4...
Low severity
Unreviewed
Published
Apr 30, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Apr 5, 2014
Published to the GitHub Advisory Database
Apr 30, 2022
Last updated
Jan 30, 2023
The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.
References