CVE-2009-1144: Code Injection
Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEMXPDFRC macro in a Gentoo build process that uses the poppler library.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1144?
CVE-2009-1144 is classified as a high-severity vulnerability due to its potential for privilege escalation by local users.
How do I fix CVE-2009-1144?
To fix CVE-2009-1144, update the Xpdf package to version 3.02-r2 or later.
Who is affected by CVE-2009-1144?
CVE-2009-1144 affects local users on systems running vulnerable versions of the Xpdf software.
What is the attack vector for CVE-2009-1144?
The attack vector for CVE-2009-1144 involves the use of a Trojan horse xpdfrc file placed in the current working directory.
What software versions are vulnerable to CVE-2009-1144?
Vulnerable versions of Xpdf include 0.5a through 3.02, prior to the patched 3.02-r2 release.