|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
|
Xpdf Information for VU#200132
| Date Notified: | 2003-05-20 |
| Date Updated: | |
| Statement Date: | |
| Status Summary: | Vulnerable |
Vendor StatementA new version of Xpdf (2.02pl1) is now available on the Xpdf web site:
http://www.foolabs.com/xpdf/
This version includes a small patch that fixes a security hole in version 2.02. It was possible to construct a malicious URL link in a PDF file which would cause an arbitrary command to be run. The patch changes things to that the various characters which can cause trouble are escaped (%xx) before calling system(). This patch also changes the "launch" link verification dialog to provide a scrolling view of the command about to be run when the command string is excessively long.
This security hole (and the patch) only affect the Unix viewer -- they do not affect the command tools on Unix, Windows, or other operating systems.Vendor InformationThe vendor has not provided us with any further information regarding this vulnerability.
AddendumThe CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |