pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pdftops | Glyph_and_cog | * | 1.1.19rc1 (including) |
Cupsys | Ubuntu | dapper | * |
Cupsys | Ubuntu | edgy | * |
Cupsys | Ubuntu | feisty | * |
Cupsys | Ubuntu | gutsy | * |
Cupsys | Ubuntu | upstream | * |