The (1) extract_keys_from_pdf and (2) fill_pdf functions in pdf_ext.py in logilab-commons before 0.61.0 allows local users to overwrite arbitrary files and possibly have other unspecified impact via a symlink attack on /tmp/toto.fdf.
References
Configurations
History
No history.
Information
Published : 2014-03-11 19:37
Updated : 2018-10-30 16:27
NVD link : CVE-2014-1838
Mitre link : CVE-2014-1838
CVE.ORG link : CVE-2014-1838
JSON object : View
Products Affected
opensuse
- opensuse
logilab
- logilab-common
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')