CVE-2007-6358
published 2007-12-15CVE-2007-6358: pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file…
PriorityP414medium4.9CVSS 2.0
AVLACLAuNCNICAN
EPSS
0.47%
37.9th percentile
pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.3.5-1 | 1.3.5-1 |
| apple | cups | >= 0 < 1.3.5-1 | 1.3.5-1 |
| apple | cups | >= 0 < 1.3.5-1 | 1.3.5-1 |
| apple | cups | >= 0 < 1.3.5-1 | 1.3.5-1 |
| debian | cups | < cups 1.3.5-1 (bookworm) | cups 1.3.5-1 (bookworm) |
| glyph_and_cog | pdftops | <= 1.1.19rc1 | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:C/A:N
osv4.9MEDIUM
vendor_debian4.9LOW
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2008-01-09
CVE-2007-5849 CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
Wei Wang discovered that the SNMP discovery backend did not
correctly calculate the length of strings. If a user were tricked into
scanning for printers, a remote attacker could send a specially crafted
packet and possibly execute arbitrary code.
Elias Pipping discovered that temporary files were not handled safely
in certain situations when converting PDF to PS. A local attacker could
cause a denial of service.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2007-6358: cups - pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwri...
vendor_debian·2007·CVSS 4.9
CVE-2007-6358 [MEDIUM] CVE-2007-6358: cups - pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwri...
pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.
Scope: local
bookworm: resolved (fixed in 1.3.5-1)
bullseye: resolved (fixed in 1.3.5-1)
forky: resolved (fixed in 1.3.5-1)
sid: resolved (fixed in 1.3.5-1)
trixie: resolved (fixed in 1.3.5-1)
Red Hat
CVE-2007-6358: pdftops
vendor_redhat·CVSS 4.9
CVE-2007-6358 [MEDIUM] CVE-2007-6358: pdftops
pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.
Statement: Not vulnerable. Red Hat Enterprise Linux versions 2.1, 3, 4 and 5 do not ship with the alternate pdftops.pl CUPS printing filter that is affected by this flaw.
GHSA
GHSA-25gm-5rg6-r2ph: pdftops
ghsa_unreviewed·2022-05-01
CVE-2007-6358 [MEDIUM] GHSA-25gm-5rg6-r2ph: pdftops
pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.
OSV
CVE-2007-6358: pdftops
osv·2007-12-15·CVSS 4.9
CVE-2007-6358 [MEDIUM] CVE-2007-6358: pdftops
pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/42029http://secunia.com/advisories/28113http://secunia.com/advisories/28139http://secunia.com/advisories/28200http://secunia.com/advisories/28386http://www.cups.org/articles.php?L515http://www.debian.org/security/2007/dsa-1437http://www.gentoo.org/security/en/glsa/glsa-200712-14.xmlhttp://www.securityfocus.com/bid/26919http://www.ubuntu.com/usn/usn-563-1https://bugs.gentoo.org/show_bug.cgi?id=201042http://osvdb.org/42029http://secunia.com/advisories/28113http://secunia.com/advisories/28139http://secunia.com/advisories/28200http://secunia.com/advisories/28386http://www.cups.org/articles.php?L515http://www.debian.org/security/2007/dsa-1437http://www.gentoo.org/security/en/glsa/glsa-200712-14.xmlhttp://www.securityfocus.com/bid/26919http://www.ubuntu.com/usn/usn-563-1https://bugs.gentoo.org/show_bug.cgi?id=201042
2007-12-15
Published