CVE-2011-1136
Executive Summary
In Tesseract OCR versions 2.03 and 2.04, an attacker can overwrite any user file by guessing the process ID and creating a symbolic link to that file. This allows arbitrary file modification without authentication, potentially leading to data loss or system compromise.
Authoritative CVE Metadata - CVSS Base Score: 4.7 (MEDIUM) - Published: 2019-11-14T01:15:10.727 - Last Modified: 2026-09-14T14:10:44.773
Original Description: In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.
"An optimist is a person who sees a green light everywhere, while the pessimist sees only the red spotlight... The truly wise person is colour-blind."
— Albert Schweitzer
Source: NVD