CVE-2000-0727: High severity xpdf Xpdf vulnerability
Published Oct 13, 2000
·Updated
xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.
Affected Software
1 affected component
xpdf Xpdf=0.90
Remediation
Patch Available
Patch Available
Event History
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0727?
CVE-2000-0727 is categorized as a medium severity vulnerability due to the potential for arbitrary command execution.
2
How do I fix CVE-2000-0727?
To mitigate CVE-2000-0727, upgrade Xpdf to version 0.91 or later where the issue has been addressed.
3
What versions of Xpdf are affected by CVE-2000-0727?
CVE-2000-0727 affects Xpdf versions earlier than 0.91, specifically including 0.90.
4
What type of attack can CVE-2000-0727 facilitate?
CVE-2000-0727 can facilitate remote command execution attacks through specially crafted URLs.
5
Is CVE-2000-0727 a local or remote vulnerability?
CVE-2000-0727 is a remote vulnerability, allowing exploitation over the network via crafted PDF files.