cbcvebase.
CVE-2008-5377
published 2008-12-08

CVE-2008-5377: pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability…

PriorityP425medium6.9CVSS 2.0
AVLACMAuNCCICAC
EXPLOIT
EPSS
0.72%
50.0th percentile
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.

Affected

6 ranges
VendorProductVersion rangeFixed in
applecups
applecups>= 0 < 1.3.8-1lenny11.3.8-1lenny1
applecups>= 0 < 1.3.8-1lenny11.3.8-1lenny1
applecups>= 0 < 1.3.8-1lenny11.3.8-1lenny1
applecups>= 0 < 1.3.8-1lenny11.3.8-1lenny1
debiancups< cups 1.3.8-1lenny1 (bookworm)cups 1.3.8-1lenny1 (bookworm)

CVSS provenance

nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv1.2LOW
vendor_ubuntu7.5HIGH
vendor_debian1.2LOW
vendor_redhat1.2LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.