Common Vulnerabilities and Exposures assigned an identifier CVE-2009-5078 to the following vulnerability: Name: CVE-2009-5078 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5078 Assigned: 20110630 Reference: http://openwall.com/lists/oss-security/2009/08/09/1 Reference: http://openwall.com/lists/oss-security/2009/08/10/2 Reference: ftp://ftp.gnu.org/gnu/groff/groff-1.20.1-1.21.diff.gz Reference: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538338 Reference: http://www.securityfocus.com/bid/36381 contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document. Statement: Not vulnerable. This issue did not affect the versions of groff as shipped with Red Hat Enterprise Linux 4, 5, or 6.
Created groff tracking bugs for this issue Affects: fedora-14 [bug 720061]