CVE-2014-1838
The (1) extract_keys_from_pdf and (2) fill_pdf functions in pdf_ext.py in logilab-commons before 0.61.0 allows local users to overwrite arbitrary files and possibly have other unspecified impact via a symlink attack on /tmp/toto.fdf.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0004 (0.0%)
Percentile: 12.7%
EPSS: 2026-05-06
Affects
opensuse:opensuselogilab:logilab-commonTechnical description
The (1) extract_keys_from_pdf and (2) fill_pdf functions in pdf_ext.py in logilab-commons before 0.61.0 allows local users to overwrite arbitrary files and possibly have other unspecified impact via a symlink attack on /tmp/toto.fdf.
Published: 3/11/2014, 7:37:04 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://comments.gmane.org/gmane.comp.security.oss.general/11986
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00085.html
- http://secunia.com/advisories/57209
- http://www.logilab.org/ticket/207561
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737051
- http://comments.gmane.org/gmane.comp.security.oss.general/11986
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00085.html
- http://secunia.com/advisories/57209