CVE-2013-4472: Low severity Freedesktop poppler vulnerability
Published Apr 22, 2014
·Updated
The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
Affected Software
4 affected components
Freedesktop poppler<=0.24.3
Freedesktop poppler=0.24.0
Freedesktop poppler=0.24.1
Freedesktop poppler=0.24.2
Event History
Apr 22, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:23 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-4472?
CVE-2013-4472 is considered a medium severity vulnerability due to the risk of local file overwrite.
2
How do I fix CVE-2013-4472?
To fix CVE-2013-4472, upgrade to a version of Poppler greater than 0.24.3.
3
Who is affected by CVE-2013-4472?
Local users on non-Unix systems using Xpdf or Poppler version 0.24.3 or earlier are affected by CVE-2013-4472.
4
What kind of attack does CVE-2013-4472 involve?
CVE-2013-4472 involves a symlink attack that allows overwriting arbitrary files via predictable temporary filenames.
5
Is CVE-2013-4472 a remote or local vulnerability?
CVE-2013-4472 is a local vulnerability, requiring authenticated access to exploit.