Lucene search

K
ubuntucveUbuntu.comUB:CVE-2007-6358
HistoryDec 15, 2007 - 12:00 a.m.

CVE-2007-6358

2007-12-1500:00:00
ubuntu.com
ubuntu.com
15

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:C/A:N

EPSS

0

Percentile

5.1%

pdftops.pl before 1.20 in alternate pdftops filter allows local users to
overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp
temporary file, which is created when pdftops reads a PDF file from stdin,
such as when pdftops is invoked by CUPS.

Bugs

Notes

Author Note
jdstrand from Debian: NOTE: the debian package is a bit confusing here as it also ships a pdftops NOTE: wrapper script as an example but the original script is installed NOTE: under /usr/lib/cups/filters
OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchcupsys< 1.2.2-0ubuntu0.6.06.6UNKNOWN
ubuntu6.10noarchcupsys< 1.2.4-2ubuntu3.2UNKNOWN
ubuntu7.04noarchcupsys< 1.2.8-0ubuntu8.2UNKNOWN
ubuntu7.10noarchcupsys< 1.3.2-1ubuntu7.3UNKNOWN

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:C/A:N

EPSS

0

Percentile

5.1%