pdftops.pl Alternate pdftops Filter for CUPS Insecure Temporary File Creation Vulnerability
BID:26919
Info
pdftops.pl Alternate pdftops Filter for CUPS Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 26919 |
| Class: | Design Error |
| CVE: |
CVE-2007-6358 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 03 2007 12:00AM |
| Updated: | Jan 09 2008 02:19PM |
| Credit: | Elias Pipping reported this issue in the Gentoo bug report. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 pdftops.pl pdftops.pl 1.10 pdftops.pl pdftops.pl 1.00 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
pdftops.pl pdftops.pl 1.20 |
Discussion
pdftops.pl Alternate pdftops Filter for CUPS Insecure Temporary File Creation Vulnerability
The 'pdftops.pl' script is prone to a security vulnerability because it creates temporary files in an insecure way.
An attacker with local access could potentially exploit this issue to perform symlink attacks.
Successfully mounting a symlink attack may allow the attacker to overwrite, delete, or corrupt sensitive files in the context of the affected application, which may result in a denial of service. Other attacks may also be possible.
This issue affects versions prior to pdftops.pl 1.20.
The 'pdftops.pl' script is prone to a security vulnerability because it creates temporary files in an insecure way.
An attacker with local access could potentially exploit this issue to perform symlink attacks.
Successfully mounting a symlink attack may allow the attacker to overwrite, delete, or corrupt sensitive files in the context of the affected application, which may result in a denial of service. Other attacks may also be possible.
This issue affects versions prior to pdftops.pl 1.20.
Exploit / POC
pdftops.pl Alternate pdftops Filter for CUPS Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit the issue.
An attacker uses readily available commands to exploit the issue.
Solution / Fix
pdftops.pl Alternate pdftops Filter for CUPS Insecure Temporary File Creation Vulnerability
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
pdftops.pl pdftops.pl 1.10
pdftops.pl pdftops.pl 1.00
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
pdftops.pl pdftops.pl 1.10
-
pdftops.pl pdftops-1.20
http://www.srz.de/Members/bla/cups/filter/pdftops/pdftops-1.20
pdftops.pl pdftops.pl 1.00
-
pdftops.pl pdftops-1.20
http://www.srz.de/Members/bla/cups/filter/pdftops/pdftops-1.20
References
pdftops.pl Alternate pdftops Filter for CUPS Insecure Temporary File Creation Vulnerability
References:
References: