—
PYSEC-2014-83
Quick fix
PYSEC-2014-83 — logilab-common: upgrade to the fixed version with the command below.
pip install --upgrade 'logilab-common>=0.60.1'Details
The (1) extract_keys_from_pdf and (2) fill_pdf functions in pdf_ext.py in logilab-commons before 0.61.0 allows local users to overwrite arbitrary files and possibly have other unspecified impact via a symlink attack on /tmp/toto.fdf.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/logilab-common
Introduced in:
0Fixed in: 0.60.1Fix
pip install --upgrade 'logilab-common>=0.60.1'References
- http://comments.gmane.org/gmane.comp.security.oss.general/11986[WEB]
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737051[WEB]
- http://secunia.com/advisories/57209[ADVISORY]
- http://www.logilab.org/ticket/207561[WEB]
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00085.html[WEB]
- https://github.com/advisories/GHSA-rr52-wg7f-8875[ADVISORY]