Vulnerability Description
pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Glyph And Cog | Pdftops | <= 1.1.19rc1 |
References
- http://osvdb.org/42029
- http://secunia.com/advisories/28113Vendor Advisory
- http://secunia.com/advisories/28139Vendor Advisory
- http://secunia.com/advisories/28200Vendor Advisory
- http://secunia.com/advisories/28386Vendor Advisory
- http://www.cups.org/articles.php?L515
- http://www.debian.org/security/2007/dsa-1437
- http://www.gentoo.org/security/en/glsa/glsa-200712-14.xml
- http://www.securityfocus.com/bid/26919
- http://www.ubuntu.com/usn/usn-563-1
- https://bugs.gentoo.org/show_bug.cgi?id=201042Exploit
- http://osvdb.org/42029
- http://secunia.com/advisories/28113Vendor Advisory
- http://secunia.com/advisories/28139Vendor Advisory
- http://secunia.com/advisories/28200Vendor Advisory
FAQ
What is CVE-2007-6358?
CVE-2007-6358 is a vulnerability with a CVSS score of 4.9 (MEDIUM). pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF...
How severe is CVE-2007-6358?
CVE-2007-6358 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-6358?
Check the references section above for vendor advisories and patch information. Affected products include: Glyph And Cog Pdftops.