The (1) extract_keys_from_pdf and (2) fill_pdf functions in pdf_ext.py in logilab-commons before 0.61.0 allows local users to overwrite arbitrary files and possibly have other unspecified impact via a symlink attack on /tmp/toto.fdf.
References
Configurations
History
No history.
Information
Published : 2014-03-11 19:37
Updated : 2024-02-04 18:35
NVD link : CVE-2014-1838
Mitre link : CVE-2014-1838
CVE.ORG link : CVE-2014-1838
JSON object : View
Products Affected
logilab
- logilab-common
opensuse
- opensuse
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')