First published: Fri Oct 13 2000(Updated: )
xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xpdf | =0.90 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0727 is categorized as a medium severity vulnerability due to the potential for arbitrary command execution.
To mitigate CVE-2000-0727, upgrade Xpdf to version 0.91 or later where the issue has been addressed.
CVE-2000-0727 affects Xpdf versions earlier than 0.91, specifically including 0.90.
CVE-2000-0727 can facilitate remote command execution attacks through specially crafted URLs.
CVE-2000-0727 is a remote vulnerability, allowing exploitation over the network via crafted PDF files.