CVE-2015-7758

NameCVE-2015-7758
DescriptionGummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the name of an existing file and a (1) .aux, (2) .log, (3) .out, (4) .pdf, or (5) .toc extension for the file name, as demonstrated by .thesis.tex.aux.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs756432

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gummi (PTS)buster0.6.6-5fixed
bullseye0.8.1-1fixed
bookworm0.8.3+really0.8.1-0.1fixed
trixie0.8.3+really0.8.3-1fixed
sid0.8.3+really0.8.3-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gummisourcewheezy0.6.3-1.2+deb7u2
gummisourcejessie0.6.5-3+deb8u1
gummisource(unstable)0.6.5-6756432

Notes

https://www.openwall.com/lists/oss-security/2015/10/08/4

Search for package or bug name: Reporting problems