First published: Tue Apr 22 2014(Updated: )
The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
freedesktop poppler | <=0.24.3 | |
freedesktop poppler | =0.24.0 | |
freedesktop poppler | =0.24.1 | |
freedesktop poppler | =0.24.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.