The (1) extract_keys_from_pdf and (2) fill_pdf functions in pdf_ext.py in logilab-commons before 0.61.0 allows local users to overwrite arbitrary files and possibly have other unspecified impact via a symlink attack on /tmp/toto.fdf.
References
Information
Published : 2014-03-11 12:37
Updated : 2018-10-30 09:27
NVD link : CVE-2014-1838
Mitre link : CVE-2014-1838
JSON object : View
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
Products Affected
logilab
- logilab-common
opensuse
- opensuse