cbcvebase.
CVE-2007-6358
published 2007-12-15

CVE-2007-6358: pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file…

PriorityP414medium4.9CVSS 2.0
AVLACLAuNCNICAN
EPSS
0.47%
37.9th percentile
pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.

Affected

6 ranges
VendorProductVersion rangeFixed in
applecups>= 0 < 1.3.5-11.3.5-1
applecups>= 0 < 1.3.5-11.3.5-1
applecups>= 0 < 1.3.5-11.3.5-1
applecups>= 0 < 1.3.5-11.3.5-1
debiancups< cups 1.3.5-1 (bookworm)cups 1.3.5-1 (bookworm)
glyph_and_cogpdftops<= 1.1.19rc1

CVSS provenance

nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:C/A:N
osv4.9MEDIUM
vendor_debian4.9LOW
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.