CVE-2018-7441
published 2018-02-23CVE-2018-7441: Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local users to overwrite arbitrary files or have unspecified other impact by creating…
PriorityP429high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.26%
17.6th percentile
Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local users to overwrite arbitrary files or have unspecified other impact by creating files in advance or winning a race condition, as demonstrated by /tmp/junk_split_image.ps in prog/splitimage2pdf.c.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | leptonlib | < leptonlib 1.76.0-1 (bookworm) | leptonlib 1.76.0-1 (bookworm) |
| leptonica | leptonica | <= 1.75.3 | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.0HIGH
vendor_debian7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ffph-9q4q-c343: Leptonica through 1
ghsa_unreviewed·2022-05-14
CVE-2018-7441 [HIGH] CWE-362 GHSA-ffph-9q4q-c343: Leptonica through 1
Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local users to overwrite arbitrary files or have unspecified other impact by creating files in advance or winning a race condition, as demonstrated by /tmp/junk_split_image.ps in prog/splitimage2pdf.c.
OSV
CVE-2018-7441: Leptonica through 1
osv·2018-02-23·CVSS 7.0
CVE-2018-7441 [HIGH] CVE-2018-7441: Leptonica through 1
Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local users to overwrite arbitrary files or have unspecified other impact by creating files in advance or winning a race condition, as demonstrated by /tmp/junk_split_image.ps in prog/splitimage2pdf.c.
Debian
CVE-2018-7441: leptonlib - Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local ...
vendor_debian·2018·CVSS 7.0
CVE-2018-7441 [HIGH] CVE-2018-7441: leptonlib - Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local ...
Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local users to overwrite arbitrary files or have unspecified other impact by creating files in advance or winning a race condition, as demonstrated by /tmp/junk_split_image.ps in prog/splitimage2pdf.c.
Scope: local
bookworm: resolved (fixed in 1.76.0-1)
bullseye: resolved (fixed in 1.76.0-1)
forky: resolved (fixed in 1.76.0-1)
sid: resolved (fixed in 1.76.0-1)
trixie: resolved (fixed in 1.76.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-7441 mingw-leptonica: leptonica: hardcoded /tmp paths [fedora-all]
bugzilla·2018-02-27·CVSS 7.0
CVE-2018-7441 [HIGH] CVE-2018-7441 mingw-leptonica: leptonica: hardcoded /tmp paths [fedora-all]
CVE-2018-7441 mingw-leptonica: leptonica: hardcoded /tmp paths [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
Bugzilla
CVE-2018-7441 leptonica: hardcoded /tmp paths [epel-all]
bugzilla·2018-02-27·CVSS 7.0
CVE-2018-7441 [HIGH] CVE-2018-7441 leptonica: hardcoded /tmp paths [epel-all]
CVE-2018-7441 leptonica: hardcoded /tmp paths [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora EPEL. While
Bugzilla
CVE-2018-7441 leptonica: hardcoded /tmp paths [fedora-all]
bugzilla·2018-02-27·CVSS 7.0
CVE-2018-7441 [HIGH] CVE-2018-7441 leptonica: hardcoded /tmp paths [fedora-all]
CVE-2018-7441 leptonica: hardcoded /tmp paths [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While o
Bugzilla
CVE-2018-7441 leptonica: hardcoded /tmp paths
bugzilla·2018-02-27·CVSS 7.0
CVE-2018-7441 [HIGH] CVE-2018-7441 leptonica: hardcoded /tmp paths
CVE-2018-7441 leptonica: hardcoded /tmp paths
Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local users to overwrite arbitrary files or have unspecified other impact by creating files in advance or winning a race condition, as demonstrated by /tmp/junk_split_image.ps in prog/splitimage2pdf.c.
References:
https://lists.debian.org/debian-lts/2018/02/msg00054.html
Discussion:
Created leptonica tracking bugs for this issue:
Affects: epel-all [bug 1549744]
Affects: fedora-all [bug 1549743]
Created mingw-leptonica tracking bugs for this issue:
Affects: fedora-all [bug 1549745]
2018-02-23
Published