CVE-2014-1838: Logilab Logilab-Common

Medium severity, CVSS 4.4. EPSS: 0.3% chance of exploitation in the next 30 days.

The (1) extract_keys_from_pdf and (2) fill_pdf functions in pdf_ext.py in logilab-commons before 0.61.0 allows local users to overwrite arbitrary files and possibly have other unspecified impact via a symlink attack on /tmp/toto.fdf.

Affected products

  • Logilab Logilab-Common: up to and including 0.60.0
  • Opensuse Opensuse: version 12.3 only; version 13.1 only

Published 2014-03-11. Last modified 2026-06-17.