CVE-2011-2902: Input Validation
zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pdf.gz file name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2902?
CVE-2011-2902 is rated as a moderate vulnerability due to its potential to allow remote attackers to delete arbitrary files.
How do I fix CVE-2011-2902?
To fix CVE-2011-2902, upgrade the xpdf package to version 3.04+git20210103-3 or later.
What systems are affected by CVE-2011-2902?
CVE-2011-2902 affects xpdf versions before 3.02-19 and Debian distributions prior to updates that fixed the issue.
What type of attack is possible with CVE-2011-2902?
CVE-2011-2902 allows remote attackers to delete arbitrary files by exploiting the insecure handling of temporary files in crafted PDF files.
Is CVE-2011-2902 specific to any operating system?
CVE-2011-2902 primarily affects Debian-based systems, including Debian GNU/Linux versions 7.0, 8.0, and 9.0.