Candidate: CVE-2011-2902 PublicDate: 2018-01-30 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2902 Description: zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pdf.gz file name. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=635849 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N [5.3 MEDIUM] Patches_xpdf: upstream_xpdf: released (3.02-19) hardy_xpdf: ignored (reached end-of-life) lucid_xpdf: ignored (reached end-of-life) maverick_xpdf: ignored (reached end-of-life) natty_xpdf: ignored (reached end-of-life) oneiric_xpdf: not-affected (3.02-21) precise_xpdf: not-affected (3.02-21build1) quantal_xpdf: not-affected (3.02-21build1) raring_xpdf: not-affected (3.02-21build1) saucy_xpdf: not-affected (3.02-21build1) devel_xpdf: not-affected (3.02-21build1)