3.3
CVSSv2

CVE-2013-4472

Published: 22/04/2014 Updated: 23/04/2014
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and previous versions, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop poppler 0.24.0

freedesktop poppler 0.24.2

freedesktop poppler 0.24.1

freedesktop poppler

Vendor Advisories

The openTempFile function in goo/gfilecc in Xpdf and Poppler 0243 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names ...