zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pdf.gz file name.
Published at: January 31, 2018 at 01:29AM
View on website
New vulnerability on the NVD: CVE-2011-2902
Tag: government hack NVD security
No comments: