Description
The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 11 | | =20.09.0-3.1 || =20.09.0-3.1+deb11u1 || =20.09.0-3.1+deb11u2 || =21.02.0-1 || =21.06.0-1 || =21.06.1-1 || =21.11.0-1 || =22.02.0-1 || =22.02.0-2 || =22.02.0-3 || =22.06.0-1 || =22.08.0-1 || =22.08.0-2 || =22.08.0-2.1 || =22.11.0-1 || =22.12.0-1 || =22.12.0-2 || =22.12.0-2.1 || =22.12.0-2.2 || =23.08.0-1 || =23.08.0-2 || =23.12.0-1 || =24.02.0-1 || =24.02.0-2 || =24.02.0-3 || =24.02.0-4 || =24.02.0-5 || =24.02.0-5+loong64 || =24.06.0-1 || =24.06.0-2 || =24.08.0-1 || =24.08.0-2 || =24.08.0-3 || =24.08.0-4 || =25.01.0-1 || =25.01.0-2 || =25.01.0-3 || =25.01.0-4 || =25.01.0-5 || =25.03.0-1 || =25.03.0-10 || =25.03.0-11 || =25.03.0-11.1 || =25.03.0-2 || =25.03.0-3 || =25.03.0-4 || =25.03.0-5 || =25.03.0-6 || =25.03.0-7 || =25.03.0-9 || =26.01.0-1 || =26.01.0-2 |
 debian 12 | | =22.12.0-2 || =22.12.0-2+deb12u1 || =22.12.0-2.1 || =22.12.0-2.2 || =23.08.0-1 || =23.08.0-2 || =23.12.0-1 || =24.02.0-1 || =24.02.0-2 || =24.02.0-3 || =24.02.0-4 || =24.02.0-5 || =24.02.0-5+loong64 || =24.06.0-1 || =24.06.0-2 || =24.08.0-1 || =24.08.0-2 || =24.08.0-3 || =24.08.0-4 || =25.01.0-1 || =25.01.0-2 || =25.01.0-3 || =25.01.0-4 || =25.01.0-5 || =25.03.0-1 || =25.03.0-10 || =25.03.0-11 || =25.03.0-11.1 || =25.03.0-2 || =25.03.0-3 || =25.03.0-4 || =25.03.0-5 || =25.03.0-6 || =25.03.0-7 || =25.03.0-9 || =26.01.0-1 || =26.01.0-2 |
 debian 11 | | =3.04+git20210103-3 || =3.04+git20211001-1 || =3.04+git20211021-1 || =3.04+git20220201-1 || =3.04+git20220601-1 || =3.04+git20231213-1 || =3.04+git20240118-1 || =3.04+git20240124-1 || =3.04+git20240202-1 || =3.04+git20240613-1 || =3.04+git20250103-1 || =3.04+git20250304-1 || =3.04+git20260220-1 |
 debian 12 | | =3.04+git20220601-1 || =3.04+git20231213-1 || =3.04+git20240118-1 || =3.04+git20240124-1 || =3.04+git20240202-1 || =3.04+git20240613-1 || =3.04+git20250103-1 || =3.04+git20250304-1 || =3.04+git20260220-1 |
 debian 13 | | =3.04+git20250304-1 || =3.04+git20260220-1 |
 debian 13 | | =25.03.0-10 || =25.03.0-11 || =25.03.0-11.1 || =25.03.0-5 || =25.03.0-5+deb13u2 || =25.03.0-6 || =25.03.0-7 || =25.03.0-9 || =26.01.0-1 || =26.01.0-2 |
 debian 14 | | =3.04+git20250304-1 || =3.04+git20260220-1 |
 debian 14 | | =25.03.0-10 || =25.03.0-11 || =25.03.0-11.1 || =25.03.0-5 || =25.03.0-6 || =25.03.0-7 || =25.03.0-9 || =26.01.0-1 || =26.01.0-2 |