—
PYSEC-2026-886
ocrodjvu is vulnerable to Arbitrary File Modification via symlink attack
Quick fix
PYSEC-2026-886 — ocrodjvu: upgrade to the fixed version with the command below.
pip install --upgrade 'ocrodjvu>=0.4.6-2'Details
ocrodjvu 0.4.6-1 on Debian GNU/Linux allows local users to modify arbitrary files via a symlink attack on temporary files that are generated when Cuneiform is invoked as the OCR engine.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2010-4338[ADVISORY]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64892[WEB]
- https://github.com/jwilk-archive/ocrodjvu[PACKAGE]
- https://web.archive.org/web/20200229160520/http://www.securityfocus.com/bid/45234[WEB]
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598134[WEB]
- https://pypi.org/project/ocrodjvu[PACKAGE]
- https://github.com/advisories/GHSA-5pjj-7m4p-wfh2[ADVISORY]