First published: Sat Dec 15 2007(Updated: )
pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Glyph & Cog pdftops | <=1.1.19rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6358 is considered to have a moderate severity rating due to its potential for local file overwriting.
To mitigate CVE-2007-6358, it is essential to update to pdftops version 1.20 or later where the symlink vulnerability is addressed.
CVE-2007-6358 affects local users operating versions of pdftops below 1.20, particularly in environments utilizing CUPS.
CVE-2007-6358 involves a symlink attack that allows local users to overwrite arbitrary files.
According to CVE-2007-6358, the vulnerable software is pdftops in versions prior to 1.20.