First published: Mon Dec 01 2008(Updated: )
chm2pdf 0.9 uses temporary files in directories with fixed names, which allows local users to cause a denial of service (chm2pdf failure) of other users by creating those directories ahead of time.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chm2pdf | =0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-5298 is categorized as a denial of service vulnerability.
To fix CVE-2008-5298, users should avoid creating directories with fixed names that chm2pdf 0.9 uses for temporary files.
Local users on systems running chm2pdf version 0.9 are affected by CVE-2008-5298.
CVE-2008-5298 enables a denial of service attack by allowing users to manipulate fixed temporary file directories.
There is no specific patch available for CVE-2008-5298; users need to change their usage patterns instead.