VYPR
Medium severity5.3NVD Advisory· Published Jan 30, 2018· Updated Jun 16, 2026

CVE-2011-2902

CVE-2011-2902

Description

zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pdf.gz file name.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • Range: < 3.02-19
  • cpe:2.3:a:glyphandcog:xpdf:*:*:*:*:*:*:*:*
    Range: <3.02-19
  • Debian/linux3 versions
    cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • Debian/xpdfllm-create
    Range: <3.02-19 (unstable), <3.02-12+squeeze1 (squeeze)
  • Xpdf/Xpdfllm-fuzzy
    Range: <3.02-19 (unstable), <3.02-12+squeeze1 (squeeze)

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.