First published: Wed Jun 18 2003(Updated: )
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | =5.0.6 | |
Xpdf | =1.1 | |
Mandriva Linux Corporate Server | =2.1 | |
Red Hat Enterprise Linux | =2.1 | |
Red Hat Linux Advanced Workstation | =2.1 | |
Red Hat Linux | =7.2 | |
Red Hat Enterprise Linux | =2.1 | |
Red Hat Linux | =8.0 | |
Red Hat Linux | =7.3 | |
Mandrake Linux | =9.0 | |
Red Hat Enterprise Linux | =2.1 | |
Red Hat Linux | =7.1 | |
Mandrake Linux | =9.1 | |
Red Hat Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0434 is considered to be a high severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2003-0434, users should update their PDF viewer software to the latest patched version.
Adobe Acrobat version 5.0.6 is affected by CVE-2003-0434, allowing potential command execution through embedded hyperlinks.
A possible workaround for CVE-2003-0434 is to disable the opening of hyperlinks in PDF viewers until the software is updated.
Yes, CVE-2003-0434 affects multiple versions of Red Hat Linux, specifically those listed in the vulnerability report.