First published: Thu Apr 09 2009(Updated: )
Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEM_XPDFRC macro in a Gentoo build process that uses the poppler library.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xpdf | =0.5a | |
Xpdf | =0.7a | |
Xpdf | =0.91a | |
Xpdf | =0.91b | |
Xpdf | =0.91c | |
Xpdf | =0.92a | |
Xpdf | =0.92b | |
Xpdf | =0.92c | |
Xpdf | =0.92d | |
Xpdf | =0.92e | |
Xpdf | =0.93a | |
Xpdf | =0.93b | |
Xpdf | =0.93c | |
Xpdf | =1.00a | |
Glyph & Cog XpdfReader | <=3.02 | |
Glyph & Cog XpdfReader | =0.2 | |
Glyph & Cog XpdfReader | =0.3 | |
Glyph & Cog XpdfReader | =0.4 | |
Glyph & Cog XpdfReader | =0.5 | |
Glyph & Cog XpdfReader | =0.6 | |
Glyph & Cog XpdfReader | =0.7 | |
Glyph & Cog XpdfReader | =0.80 | |
Glyph & Cog XpdfReader | =0.90 | |
Glyph & Cog XpdfReader | =0.91 | |
Glyph & Cog XpdfReader | =0.93 | |
Glyph & Cog XpdfReader | =1.00 | |
Glyph & Cog XpdfReader | =1.01 | |
Glyph & Cog XpdfReader | =2.00 | |
Glyph & Cog XpdfReader | =2.01 | |
Glyph & Cog XpdfReader | =2.02 | |
Glyph & Cog XpdfReader | =2.03 | |
Glyph & Cog XpdfReader | =3.00 | |
Gentoo Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1144 is classified as a high-severity vulnerability due to its potential for privilege escalation by local users.
To fix CVE-2009-1144, update the Xpdf package to version 3.02-r2 or later.
CVE-2009-1144 affects local users on systems running vulnerable versions of the Xpdf software.
The attack vector for CVE-2009-1144 involves the use of a Trojan horse xpdfrc file placed in the current working directory.
Vulnerable versions of Xpdf include 0.5a through 3.02, prior to the patched 3.02-r2 release.