Vulnerabilities > CVE-2000-0727 - Unspecified vulnerability in Xpdf 0.90
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.
Redhat
advisories |
|
References
- http://marc.info/?l=bugtraq&m=96766355023239&w=2
- http://marc.info/?l=bugtraq&m=96886599829687&w=2
- http://www.calderasystems.com/support/security/advisories/CSSA-2000-031.0.txt
- http://www.debian.org/security/2000/20000910a
- http://www.redhat.com/support/errata/RHSA-2000-060.html
- http://www.securityfocus.com/bid/1624