FreeBSD : pdfjam -- insecure temporary files (a02c9595-e018-11dd-a765-0030843d3802)

medium Nessus Plugin ID 35340

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

Secunia reports :

Some security issues have been reported in PDFjam, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

The security issues are caused due to the 'pdf90', 'pdfjoin', and 'pdfnup' scripts using temporary files in an insecure manner. This can be exploited to overwrite arbitrary files via symlink attacks.

Solution

Update the affected package.

See Also

https://bugzilla.novell.com/show_bug.cgi?id=459031

http://www.nessus.org/u?b5268bb4

Plugin Details

Severity: Medium

ID: 35340

File Name: freebsd_pkg_a02c9595e01811dda7650030843d3802.nasl

Version: 1.14

Type: local

Published: 1/12/2009

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:pdfjam, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 1/11/2009

Vulnerability Publication Date: 12/5/2008

Reference Information

CVE: CVE-2008-5743

CWE: 59

Secunia: 33278