CVE-2010-4338
ocrodjvu is vulnerable to Arbitrary File Modification via symlink attack
EPSS 0.03%
Description
ocrodjvu 0.4.6-1 on Debian GNU/Linux allows local users to modify arbitrary files via a symlink attack on temporary files that are generated when Cuneiform is invoked as the OCR engine.
How to fix CVE-2010-4338
To remediate CVE-2010-4338, upgrade the affected package to a fixed version below.
- Debian/ocrodjvu—upgrade to 0.4.6-2 or later
- PyPI/ocrodjvu—upgrade to 0.4.6-2 or later
Is CVE-2010-4338 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.4.6-2
- >= 0.4.6-1, < 0.4.6-2