USN-43-1: groff utility vulnerabilities
Posted on: 12/20/2004 05:52 PM

A groff security update has been released for Ubuntu Linux

Ubuntu Security Notice USN-43-1 December 20, 2004
groff vulnerabilities,

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)

The following packages are affected:


The problem can be corrected by upgrading the affected package to version In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

Javier Fernendez-Sanguino Pefa discovered that the auxiliary scripts "eqn2graph" and "pic2graph" created temporary files in an insecure way, which allowed exploitation of a race condition to create or overwrite files with the privileges of the user invoking the program.

Source archives:
Size/MD5: 122991 0d247788b6e83f87718c996f0fd05e41
Size/MD5: 715 92ca1b33ea0907aa6d4eda3db4930c51
Size/MD5: 2260623 511dbd64b67548c99805f1521f82cc5e

amd64 architecture (Athlon64, Opteron, EM64T Xeon)
Size/MD5: 856342 920534f39127c7216e62b1122fbe3c18
Size/MD5: 1890064 f012658b3b6a9aaf9151dd9aa34cc3d1

i386 architecture (x86 compatible Intel/AMD)
Size/MD5: 807612 52dc8a36fd9838ff546a2b09e48f6b12
Size/MD5: 1843076 677a86c7457eed2880100c122bcc75fd

powerpc architecture (Apple Macintosh G3/G4/G5)
Size/MD5: 860678 b2a2a921dcdbb0acc520c7de969a5104
Size/MD5: 1885062 e97f22decb7cc85fb32d76bc29f6d89a

Printed from Linux Compatible (