CVE-2013-4472

The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.3 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:N/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
VendorProductVersion
freedesktoppoppler
𝑥
≤ 0.24.3
freedesktoppoppler
0.24.0
freedesktoppoppler
0.24.1
freedesktoppoppler
0.24.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
poppler
bullseye (security)
unimportant
bullseye
unimportant
bookworm
unimportant
sid
unimportant
trixie
unimportant
xpdf
bullseye
unimportant
bookworm
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ipe
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
lucid
not-affected
libextractor
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
lucid
not-affected
poppler
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
lucid
not-affected
xpdf
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
lucid
not-affected