US-CERT
Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information
 

 View Notes By
Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric

 Other Documents
Technical Alerts

Technical Bulletins

Alerts

Security Tips

Xpdf Information for VU#200132

Date Notified:2003-05-20
Date Updated:
Statement Date:
Status Summary:Vulnerable

Vendor Statement

A new version of Xpdf (2.02pl1) is now available on the Xpdf web site:

http://www.foolabs.com/xpdf/

This version includes a small patch that fixes a security hole in version 2.02. It was possible to construct a malicious URL link in a PDF file which would cause an arbitrary command to be run. The patch changes things to that the various characters which can cause trouble are escaped (%xx) before calling system(). This patch also changes the "launch" link verification dialog to provide a scrolling view of the command about to be run when the command string is excessively long.

This security hole (and the patch) only affect the Unix viewer -- they do not affect the command tools on Unix, Windows, or other operating systems.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

Produced 2009 by US-CERT, a government organization
Disclaimers and copyright information