First published: Tue Nov 24 2009(Updated: )
The printing functionality in Microsoft Internet Explorer 8 allows remote attackers to discover a local pathname, and possibly a local username, by reading the dc:title element of a PDF document that was generated from a local web page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =8 | |
Internet Explorer | =5 | |
Internet Explorer | =7 | |
Internet Explorer | =6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4073 is considered a moderate severity vulnerability as it allows attackers to discover sensitive local pathnames.
CVE-2009-4073 allows remote attackers to read the dc:title element of a PDF document generated from a local webpage, potentially revealing local pathnames.
CVE-2009-4073 affects Internet Explorer versions 6, 7, 8, and also version 5.
To mitigate CVE-2009-4073, users should update their Internet Explorer to the latest version or apply any available security patches.
CVE-2009-4073 can compromise user privacy by potentially disclosing local filenames and paths to remote attackers.