CVE-2013-4472: Freedesktop Poppler

Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

Affected products

  • Freedesktop Poppler: up to and including 0.24.3; version 0.24.0 only; version 0.24.1 only; version 0.24.2 only

Published 2014-04-22. Last modified 2026-06-16.