|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
|
Debian Information for VU#200132
| Date Notified: | 2003-05-15 |
| Date Updated: | |
| Statement Date: | |
| Status Summary: | Vulnerable |
Vendor StatementIn Debian 2.2 (potato) and Debian 3.0 (woody), the URL loading feature of xpdf is disabled per default, but the bug is present if the user explicitly changes the configuration.
In Debian 3.0 (woody), an example urlCommand is supplied (which is commented out). This example quotes the argument against interpretation of shell metacharacters:
#urlCommand "netscape -remote 'openURL(%s)'"
(though execution of other netscape -remote commands may be possible if this command is uncommented and used)
In Debian 'testing' and 'unstable' (xpdf 2.02-2), xpdf is configured to quote the argument in urlCommand:
urlCommand "sensible-browser '%s'"Vendor InformationThe vendor has not provided us with any further information regarding this vulnerability.
AddendumThe CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |