# CVE-2001-1593

## Summary

- **CVE ID:** CVE-2001-1593
- **Severity:** UNKNOWN
- **CVSS Score:** 0.01
- **CWE:** N/A
- **Published:** Apr 5, 2014
- **Last Modified:** Mar 16, 2026

## Description

The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737385)
- [CNA](http://pkgs.fedoraproject.org/cgit/a2ps.git/plain/a2ps-4.13-security.patch)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=1060630)
- [CNA](http://seclists.org/oss-sec/2014/q1/253)
- [CNA](http://seclists.org/oss-sec/2014/q1/257)
- [CNA](http://www.debian.org/security/2014/dsa-2892)
- [CNA](http://seclists.org/oss-sec/2014/q1/237)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 31.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._