cbcvebase.
CVE-2011-1136
published 2019-11-14

CVE-2011-1136: In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.

PriorityP422medium4.7CVSS 3.1
AVLACHPRLUINSUCNIHAN
EPSS
0.45%
37.1th percentile
In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debiantesseract< tesseract 2.04-2.1 (bookworm)tesseract 2.04-2.1 (bookworm)
tesseract_projecttesseract
tesseract_projecttesseract
tesseract_projecttesseract>= 0 < 2.04-2.12.04-2.1
tesseract_projecttesseract>= 0 < 2.04-2.12.04-2.1
tesseract_projecttesseract>= 0 < 2.04-2.12.04-2.1
tesseract_projecttesseract>= 0 < 2.04-2.12.04-2.1

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.06.3MEDIUMAV:L/AC:M/Au:N/C:N/I:C/A:C
osv4.7MEDIUM
vendor_debian4.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.