CVE-2008-1693: Input Validation
The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1693?
CVE-2008-1693 has a moderate severity rating due to its potential to allow remote code execution via crafted PDF files.
How do I fix CVE-2008-1693?
To fix CVE-2008-1693, update Poppler to version 0.8.0 or later where the vulnerability is addressed.
What software is affected by CVE-2008-1693?
CVE-2008-1693 affects several applications that use the Poppler library, including Xpdf, Evince, and ePDFview.
Can CVE-2008-1693 be exploited remotely?
Yes, CVE-2008-1693 can be exploited remotely by attackers through specially crafted PDF files containing malicious fonts.
What type of vulnerability is CVE-2008-1693?
CVE-2008-1693 is a vulnerability related to improper handling of embedded fonts in PDF files.