CVE-2013-4472

EUVD-2013-4340
The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:N/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
Affected Products (NVD)
VendorProductVersion
freedesktoppoppler
𝑥
≤ 0.24.3
freedesktoppoppler
0.24.0
freedesktoppoppler
0.24.1
freedesktoppoppler
0.24.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
poppler
bookworm
unimportant
bullseye
unimportant
bullseye (security)
unimportant
sid
unimportant
trixie
unimportant
xpdf
bookworm
unimportant
bullseye
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ipe
lucid
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
libextractor
lucid
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
poppler
lucid
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
xpdf
lucid
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected