CVE-2007-6358: Medium severity Glyph And Cog Pdftops vulnerability
pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6358?
CVE-2007-6358 is considered to have a moderate severity rating due to its potential for local file overwriting.
How do I fix CVE-2007-6358?
To mitigate CVE-2007-6358, it is essential to update to pdftops version 1.20 or later where the symlink vulnerability is addressed.
Who is affected by CVE-2007-6358?
CVE-2007-6358 affects local users operating versions of pdftops below 1.20, particularly in environments utilizing CUPS.
What type of attack does CVE-2007-6358 involve?
CVE-2007-6358 involves a symlink attack that allows local users to overwrite arbitrary files.
What software is vulnerable according to CVE-2007-6358?
According to CVE-2007-6358, the vulnerable software is pdftops in versions prior to 1.20.