UBUNTU-CVE-2012-2120

Source
https://ubuntu.com/security/CVE-2012-2120
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-2120.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2012-2120
Upstream
Published
2012-05-18T22:55:00Z
Modified
2025-07-16T07:30:53.826692Z
Severity
  • Ubuntu - negligible
Summary
[none]
Details

latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

References

Affected packages

Ubuntu:14.04:LTS / texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/ubuntu/texlive-bin@2013.20130729.30972-2build3?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2013.20130729.30972-2build3

Affected versions

2013.*

2013.20130529.30792-1build2
2013.20130729.30972-2
2013.20130729.30972-2build1
2013.20130729.30972-2build2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libkpathsea-dev",
            "binary_version": "2013.20130729.30972-2build3"
        },
        {
            "binary_name": "libkpathsea6",
            "binary_version": "2013.20130729.30972-2build3"
        },
        {
            "binary_name": "libptexenc-dev",
            "binary_version": "2013.20130729.30972-2build3"
        },
        {
            "binary_name": "libptexenc1",
            "binary_version": "2013.20130729.30972-2build3"
        },
        {
            "binary_name": "texlive-binaries",
            "binary_version": "2013.20130729.30972-2build3"
        }
    ]
}