Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Untriaged
created 1 month ago
foomatic-rip filter, all versions, used insecurely creates temporary files for …

foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter.

Affected products

foomatic-filters
  • ==all versions

Matching in nixpkgs

Package maintainers