CVE-2014-1838
Severity CVSS v4.0:
Pending analysis
Type:
CWE-59
Link Following
Publication date:
11/03/2014
Last modified:
12/04/2025
Description
The (1) extract_keys_from_pdf and (2) fill_pdf functions in pdf_ext.py in logilab-commons before 0.61.0 allows local users to overwrite arbitrary files and possibly have other unspecified impact via a symlink attack on /tmp/toto.fdf.
Impact
Base Score 2.0
4.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:* | ||
| cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:logilab:logilab-common:*:*:*:*:*:*:*:* | 0.60.0 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://comments.gmane.org/gmane.comp.security.oss.general/11986
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00085.html
- http://secunia.com/advisories/57209
- http://www.logilab.org/ticket/207561
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737051
- http://comments.gmane.org/gmane.comp.security.oss.general/11986
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00085.html
- http://secunia.com/advisories/57209
- http://www.logilab.org/ticket/207561
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737051



