6.9

CVE-2009-1144

Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEM_XPDFRC macro in a Gentoo build process that uses the poppler library.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FoolabsXpdf Version0.5a
   GentooGentoo Linux
FoolabsXpdf Version0.7a
   GentooGentoo Linux
FoolabsXpdf Version0.91a
   GentooGentoo Linux
FoolabsXpdf Version0.91b
   GentooGentoo Linux
FoolabsXpdf Version0.91c
   GentooGentoo Linux
FoolabsXpdf Version0.92a
   GentooGentoo Linux
FoolabsXpdf Version0.92b
   GentooGentoo Linux
FoolabsXpdf Version0.92c
   GentooGentoo Linux
FoolabsXpdf Version0.92d
   GentooGentoo Linux
FoolabsXpdf Version0.92e
   GentooGentoo Linux
FoolabsXpdf Version0.93a
   GentooGentoo Linux
FoolabsXpdf Version0.93b
   GentooGentoo Linux
FoolabsXpdf Version0.93c
   GentooGentoo Linux
FoolabsXpdf Version1.00a
   GentooGentoo Linux
GlyphandcogXpdfreader Version <= 3.02
   GentooGentoo Linux
GlyphandcogXpdfreader Version0.2
   GentooGentoo Linux
GlyphandcogXpdfreader Version0.3
   GentooGentoo Linux
GlyphandcogXpdfreader Version0.4
   GentooGentoo Linux
GlyphandcogXpdfreader Version0.5
   GentooGentoo Linux
GlyphandcogXpdfreader Version0.6
   GentooGentoo Linux
GlyphandcogXpdfreader Version0.7
   GentooGentoo Linux
GlyphandcogXpdfreader Version0.80
   GentooGentoo Linux
GlyphandcogXpdfreader Version0.90
   GentooGentoo Linux
GlyphandcogXpdfreader Version0.91
   GentooGentoo Linux
GlyphandcogXpdfreader Version0.93
   GentooGentoo Linux
GlyphandcogXpdfreader Version1.00
   GentooGentoo Linux
GlyphandcogXpdfreader Version1.01
   GentooGentoo Linux
GlyphandcogXpdfreader Version2.00
   GentooGentoo Linux
GlyphandcogXpdfreader Version2.01
   GentooGentoo Linux
GlyphandcogXpdfreader Version2.02
   GentooGentoo Linux
GlyphandcogXpdfreader Version2.03
   GentooGentoo Linux
GlyphandcogXpdfreader Version3.00
   GentooGentoo Linux
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.23
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.