First published: Fri Apr 18 2008(Updated: )
The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Poppler Poppler | =0.3.2 | |
Poppler Poppler | =0.4.0 | |
Poppler Poppler | =0.7.1 | |
Poppler Poppler | =0.6.1 | |
Poppler Poppler | =0.3.1 | |
Poppler Poppler | =0.5.2 | |
Poppler Poppler | =0.5.91 | |
Poppler Poppler | =0.6.0 | |
Poppler Poppler | =0.3.3 | |
Poppler Poppler | =0.4.2 | |
Poppler Poppler | =0.6.4 | |
Poppler Poppler | =0.1.2 | |
Poppler Poppler | =0.7.0 | |
Poppler Poppler | =0.7.2 | |
Poppler Poppler | =0.5.0 | |
Poppler Poppler | =0.5.9 | |
Poppler Poppler | =0.6.3 | |
Poppler Poppler | =0.2.0 | |
Poppler Poppler | =0.5.4 | |
Poppler Poppler | =0.1.1 | |
Poppler Poppler | <=0.7.3 | |
Poppler Poppler | =0.4.1 | |
Poppler Poppler | =0.5.3 | |
Poppler Poppler | =0.4.4 | |
Poppler Poppler | =0.3.0 | |
Poppler Poppler | =0.1 | |
Poppler Poppler | =0.6.2 | |
Poppler Poppler | =0.4.3 | |
Poppler Poppler | =0.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1693 has a moderate severity rating due to its potential to allow remote code execution via crafted PDF files.
To fix CVE-2008-1693, update Poppler to version 0.8.0 or later where the vulnerability is addressed.
CVE-2008-1693 affects several applications that use the Poppler library, including Xpdf, Evince, and ePDFview.
Yes, CVE-2008-1693 can be exploited remotely by attackers through specially crafted PDF files containing malicious fonts.
CVE-2008-1693 is a vulnerability related to improper handling of embedded fonts in PDF files.