CVE-2008-5843

Publication date 5 January 2009

Last updated 24 July 2024


Ubuntu priority

Multiple untrusted search path vulnerabilities in pdfjam allow local users to gain privileges via a Trojan horse program in (1) the current working directory or (2) /var/tmp, related to the (a) pdf90, (b) pdfjoin, and (c) pdfnup scripts.

Read the notes from the security team

Status

Package Ubuntu Release Status
pdfjam 8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
6.06 LTS dapper
Not affected

Notes


mdeslaur

we carry a debian patch that randomizes filenames (debian #510584)