---
id: CVE-2010-4338
aliases:
  - GHSA-5pjj-7m4p-wfh2
  - PYSEC-2026-886
title: ocrodjvu is vulnerable to Arbitrary File Modification via symlink attack
summary: ocrodjvu is vulnerable to Arbitrary File Modification via symlink attack
severity: medium
vendor: ocrodjvu
product: ocrodjvu
ecosystem: pip
affected:
  - 'ocrodjvu >= 0.4.6-1, < 0.4.6-2'
patched:
  - ocrodjvu 0.4.6-2
published: '2022-05-17'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-5pjj-7m4p-wfh2'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2010-4338'
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/64892'
  - url: 'https://github.com/jwilk-archive/ocrodjvu'
  - url: >-
      https://web.archive.org/web/20200229160520/http://www.securityfocus.com/bid/45234
  - url: 'http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598134'
tags:
  - osv
  - pip
epss: 0.00317
epssPercentile: 0.24839
ingestedAt: '2026-07-08T18:25:46.048Z'
---

## Overview

ocrodjvu 0.4.6-1 on Debian GNU/Linux allows local users to modify arbitrary files via a symlink attack on temporary files that are generated when Cuneiform is invoked as the OCR engine.

## Affected packages

- `ocrodjvu >= 0.4.6-1, < 0.4.6-2`

## Remediation

Upgrade to a patched release:

- `ocrodjvu 0.4.6-2`
