latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2012-05-18T22:00:00Z

Updated: 2024-09-16T16:28:56.219Z

Reserved: 2012-04-04T00:00:00Z

Link: CVE-2012-2120

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2012-05-18T22:55:03.247

Modified: 2025-04-11T00:51:21.963

Link: CVE-2012-2120

cve-icon Redhat

No data.