Vulnerability Name: | CVE-2013-4472 (CCN-88307) | ||||||||
Assigned: | 2013-10-26 | ||||||||
Published: | 2013-10-26 | ||||||||
Updated: | 2014-04-23 | ||||||||
Summary: | The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names. | ||||||||
CVSS v3 Severity: | 5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 3.3 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P) 2.8 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:POC/RL:U/RC:UR)
2.8 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:POC/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-59 | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-4472 Source: OSVDB Type: UNKNOWN 99064 Source: CCN Type: Poppler Web Site Poppler Source: CONFIRM Type: UNKNOWN http://poppler.freedesktop.org/releases.html Source: CCN Type: oss-sec Mailing List, Sat, 26 Oct 2013 21:45:56 +0100 CVE request: 3 vulnerabilities in poppler and 1 in Xpdf Source: MLIST Type: UNKNOWN [oss-security] 20131026 CVE request: 3 vulnerabilities in poppler and 1 in Xpdf Source: MLIST Type: UNKNOWN [oss-security] 20131028 Re: CVE request: 3 vulnerabilities in poppler and 1 in Xpdf Source: CCN Type: Xpdf Web Site Xpdf Source: CCN Type: OSVDB ID: 99064 Poppler goo/gfile.cc openTempFile Function Insecure Temporary File Symlink Arbitrary File Overwrite Source: CCN Type: BID-63365 Poppler and Xpdf Insecure Temporary File Creation Vulnerability Source: XF Type: UNKNOWN poppler-xpdf-symlink(88307) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |