6.9

CVE-2009-1144

Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEM_XPDFRC macro in a Gentoo build process that uses the poppler library.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Foolabs ≫ Xpdf Version 0.5a
   Gentoo ≫ Gentoo Linux
Foolabs ≫ Xpdf Version 0.7a
   Gentoo ≫ Gentoo Linux
Foolabs ≫ Xpdf Version 0.91a
   Gentoo ≫ Gentoo Linux
Foolabs ≫ Xpdf Version 0.91b
   Gentoo ≫ Gentoo Linux
Foolabs ≫ Xpdf Version 0.91c
   Gentoo ≫ Gentoo Linux
Foolabs ≫ Xpdf Version 0.92a
   Gentoo ≫ Gentoo Linux
Foolabs ≫ Xpdf Version 0.92b
   Gentoo ≫ Gentoo Linux
Foolabs ≫ Xpdf Version 0.92c
   Gentoo ≫ Gentoo Linux
Foolabs ≫ Xpdf Version 0.92d
   Gentoo ≫ Gentoo Linux
Foolabs ≫ Xpdf Version 0.92e
   Gentoo ≫ Gentoo Linux
Foolabs ≫ Xpdf Version 0.93a
   Gentoo ≫ Gentoo Linux
Foolabs ≫ Xpdf Version 0.93b
   Gentoo ≫ Gentoo Linux
Foolabs ≫ Xpdf Version 0.93c
   Gentoo ≫ Gentoo Linux
Foolabs ≫ Xpdf Version 1.00a
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version <= 3.02
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 0.2
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 0.3
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 0.4
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 0.5
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 0.6
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 0.7
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 0.80
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 0.90
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 0.91
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 0.93
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 1.00
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 1.01
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 2.00
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 2.01
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 2.02
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 2.03
   Gentoo ≫ Gentoo Linux
Glyphandcog ≫ Xpdfreader Version 3.00
   Gentoo ≫ Gentoo Linux
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.316
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://bugs.gentoo.org/show_bug.cgi?id=200023
Vendor Advisory
http://bugs.gentoo.org/show_bug.cgi?id=242930
Vendor Advisory
http://osvdb.org/53529
http://secunia.com/advisories/34610
Vendor Advisory
http://security.gentoo.org/glsa/glsa-200904-07.xml
http://www.securityfocus.com/bid/34401