CVE-2007-6358

Publication date 15 December 2007

Last updated 24 July 2024


Ubuntu priority

pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.

Read the notes from the security team

Status

Package Ubuntu Release Status
cupsys 7.10 gutsy
Fixed 1.3.2-1ubuntu7.3
7.04 feisty
Fixed 1.2.8-0ubuntu8.2
6.10 edgy
Fixed 1.2.4-2ubuntu3.2
6.06 LTS dapper
Fixed 1.2.2-0ubuntu0.6.06.6

Notes


jdstrand

from Debian: NOTE: the debian package is a bit confusing here as it also ships a pdftops NOTE: wrapper script as an example but the original script is installed NOTE: under /usr/lib/cups/filters

References

Related Ubuntu Security Notices (USN)

    • USN-563-1
    • CUPS vulnerabilities
    • 9 January 2008

Other references