CVE-2010-4338: Medium severity jwilk ocrodjvu vulnerability
Published Jan 20, 2011
·Updated
ocrodjvu 0.4.6-1 on Debian GNU/Linux allows local users to modify arbitrary files via a symlink attack on temporary files that are generated when Cuneiform is invoked as the OCR engine.
Affected Software
5 affected componentsFixes available
pip/ocrodjvu=0.4.6-1
0.4.6-2
Jwilk Ocrodjvu=0.4.6-1
Debian Linux
All of the following
Jwilk Ocrodjvu=0.4.6-1
Debian Linux
Event History
Jan 20, 2011
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
07:00 PM
DescriptionWeaknessAffected Software
May 17, 2022
Advisory Published
via GitHub·02:04 AM
Frequently Asked Questions
1
What is the severity of CVE-2010-4338?
CVE-2010-4338 is considered to have moderate severity due to its potential for local privilege escalation.
2
How do I fix CVE-2010-4338?
To fix CVE-2010-4338, upgrade to ocrodjvu version 0.4.6-2 or later.
3
What type of attack is CVE-2010-4338?
CVE-2010-4338 is vulnerable to a symlink attack that allows local users to modify arbitrary files.
4
Which versions of ocrodjvu are affected by CVE-2010-4338?
CVE-2010-4338 affects ocrodjvu version 0.4.6-1.
5
Can CVE-2010-4338 be exploited remotely?
CVE-2010-4338 cannot be exploited remotely as it requires local user access.