CVE-2011-2902
EUVD-2011-287530.01.2018, 20:29
zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pdf.gz file name.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| glyphandcog | xpdf | 𝑥 < 3.02-19 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References