ocrodjvu@0.13.1 vulnerabilities

OCR for DjVu (Python 3 fork)

Direct Vulnerabilities

Known vulnerabilities in the ocrodjvu package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Symlink Attack

ocrodjvu is an OCR for DjVu (Python 3 fork)

Affected versions of this package are vulnerable to Symlink Attack due to the improper handling of temporary files when invoking Cuneiform as the OCR engine. An attacker can modify arbitrary files via a symlink attack on these temporary files.

Note:

This is only exploitable if the attacker has local access to the system.

How to fix Symlink Attack?

There is no fixed version for ocrodjvu.

[0,)