ocrodjvu 0.4.6-1 on Debian GNU/Linux allows local users to modify arbitrary files via a symlink attack on temporary files that are generated when Cuneiform is invoked as the OCR engine.
{ "urgency": "low" }
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2010-4338.json"