test-pipe-to-pyodconverter.org.sh in docvert 2.4 allows...
Moderate severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Nov 18, 2008
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Jan 27, 2023
test-pipe-to-pyodconverter.org.sh in docvert 2.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/outer.odt temporary file.
References