CVE-2014-1838

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
11/03/2014
Last modified:
12/04/2025

Description

The (1) extract_keys_from_pdf and (2) fill_pdf functions in pdf_ext.py in logilab-commons before 0.61.0 allows local users to overwrite arbitrary files and possibly have other unspecified impact via a symlink attack on /tmp/toto.fdf.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:a:logilab:logilab-common:*:*:*:*:*:*:*:* 0.60.0 (including)