LWN.net Logo

pdfjam: multiple vulnerabilities

Package(s):pdfjam CVE #(s):CVE-2008-5843 CVE-2008-5743
Created:March 9, 2009 Updated:March 13, 2009
Description:

From the Gentoo advisory:

* Martin Vaeth reported multiple untrusted search path vulnerabilities (CVE-2008-5843).

* Marcus Meissner of the SUSE Security Team reported that temporary files are created with a predictable name (CVE-2008-5743).

A local attacker could place a specially crafted Python module in the current working directory or the /var/tmp directory, and entice a user to run the PDFjam scripts, leading to the execution of arbitrary code with the privileges of the user running the application. A local attacker could also leverage symlink attacks to overwrite arbitrary files.

Alerts:
Fedora FEDORA-2009-2655 2009-03-13
Fedora FEDORA-2009-2651 2009-03-13
Gentoo 200903-05 2009-03-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds