ocrodjvu@0.13 vulnerabilities
OCR for DjVu (Python 3 fork)
-
latest version
0.13.1
-
first published
2 years ago
-
latest version published
6 months ago
-
licenses detected
- [0,)
Direct Vulnerabilities
Known vulnerabilities in the ocrodjvu package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
ocrodjvu is an OCR for DjVu (Python 3 fork) Affected versions of this package are vulnerable to Symlink Attack due to the improper handling of temporary files when invoking Cuneiform as the OCR engine. An attacker can modify arbitrary files via a symlink attack on these temporary files. Note: This is only exploitable if the attacker has local access to the system. How to fix Symlink Attack? There is no fixed version for |
[0,)
|