1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




PDFjam Insecure Temporary Files

Report ID: SA200800141
Source: Secunia
Date of Discovery: 26.12.2008
Criticality: Low
Affects:
PDFjam 1.x

Compromise From: Local system
Compromise Type: Privilege escalation

Summary

Some security issues have been reported in PDFjam, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Detailed Description

The security issues are caused due to the "pdf90", "pdfjoin", and "pdfnup" scripts using temporary files in an insecure manner. This can be exploited to overwrite arbitrary files via symlink attacks.

Solution

Restrict local access to trusted users only.