Multiple Linux Vendor Xpdf Embedded URL Vulnerability
BID:1624
Info
Multiple Linux Vendor Xpdf Embedded URL Vulnerability
| Bugtraq ID: | 1624 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 29 2000 12:00AM |
| Updated: | Aug 29 2000 12:00AM |
| Credit: | Discussed in Mandrake Advisory MDKSA-2000:041. |
| Vulnerable: |
Xpdf Xpdf 0.90 |
| Not Vulnerable: |
Xpdf Xpdf 0.91 |
Discussion
Multiple Linux Vendor Xpdf Embedded URL Vulnerability
When a user clicks a URL, xpdf 0.90 and earlier starts the viewer (netscape by default) but does not properly handle shell meta characters, making it possible for to embed malicious code within PDF files.
As well, these versions create files in /tmp insecurely, raising the possibility of symbolic link attacks.
When a user clicks a URL, xpdf 0.90 and earlier starts the viewer (netscape by default) but does not properly handle shell meta characters, making it possible for to embed malicious code within PDF files.
As well, these versions create files in /tmp insecurely, raising the possibility of symbolic link attacks.
Exploit / POC
Multiple Linux Vendor Xpdf Embedded URL Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Linux Vendor Xpdf Embedded URL Vulnerability
Solution:
An update, version 0.91, is available from the vendor. As this is a general bugfix release, upgrading is recommented.
Mandrake, Redhat, Caldera and Connectiva have provided RPMs of Xpdf 0.91.
Xpdf Xpdf 0.90
Solution:
An update, version 0.91, is available from the vendor. As this is a general bugfix release, upgrading is recommented.
Mandrake, Redhat, Caldera and Connectiva have provided RPMs of Xpdf 0.91.
Xpdf Xpdf 0.90
-
Caldera eDesktop 2.4: xpdf-0.91-3.i386
Upgrade the affected packages with the following commands: rpm -Fhv xpdf-0.91-3.i386.rpm
ftp://ftp.calderasystems.com/pub/updates/eDesktop/2.4/current/RPMS/xpd f-0.91-3.i386.rpm -
Caldera eServer 2.3/eBuilder 3.0: xpdf-0.91-3.i386
Upgrade the affected packages with the following commands: rpm -Fhv xpdf-0.91-3.i386.rpm
ftp://ftp.calderasystems.com/pub/updates/eServer/2.3/current/RPMS/xpdf -0.91-3.i386.rpm -
Caldera xpdf-0.91-3.i386
Upgrade the affected packages with the following command: rpm -Fhv xpdf-0.91-3.i386.rpm
ftp://ftp.calderasystems.com/pub/updates/OpenLinux/2.3/current/RPMS/xp df-0.91-3.i386.rpm -
Conectiva 4.0es i386 xpdf-0.91-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.0es/i386/xpdf-0.91-1cl.i386.rpm -
Conectiva 4.1 i386 xpdf-0.91-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.1/i386/xpdf-0.91-1cl.i386.rpm -
Conectiva 4.2 i386 xpdf-0.91-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.2/i386/xpdf-0.91-1cl.i386.rpm -
Conectiva 5.0 i386 xpdf-0.91-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/xpdf-0.91-1cl.i386.rpm -
Conectiva 5.1 i386 xpdf-0.91-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/xpdf-0.91-1cl.i386.rpm -
MandrakeSoft 6.0 i386 xpdf-0.91-2mdk.i586.rpm
ftp://ftp.linux.tucows.com/pub/distributions/Mandrake/Mandrake/updates /6.0/RPMS/xpdf-0.91-2mdk.i586.rpm -
MandrakeSoft 6.1 i386 xpdf-0.91-2mdk.i586.rpm
ftp://ftp.linux.tucows.com/pub/distributions/Mandrake/Mandrake/updates /6.1/RPMS/xpdf-0.91-2mdk.i586.rpm -
MandrakeSoft 7.0 i386 xpdf-0.91-2mdk.i586.rpm
ftp://ftp.linux.tucows.com/pub/distributions/Mandrake/Mandrake/updates /7.0/RPMS/xpdf-0.91-2mdk.i586.rpm -
MandrakeSoft 7.1 i386 xpdf-0.91-2mdk.i586.rpm
ftp://ftp.linux.tucows.com/pub/distributions/Mandrake/Mandrake/updates /7.1/RPMS/xpdf-0.91-2mdk.i586.rpm -
Red Hat Inc. 5.2 alpha xpdf-0.91-1.5x.alpha.rpm
ftp://updates.redhat.com/5.2/alpha/xpdf-0.91-1.5x.alpha.rpm -
Red Hat Inc. 5.2 i386 xpdf-0.91-1.5x.i386.rpm
ftp://updates.redhat.com/5.2/i386/xpdf-0.91-1.5x.i386.rpm -
Red Hat Inc. 5.2 source xpdf-0.91-1.5x.src.rpm
ftp://updates.redhat.com/5.2/SRPMS/xpdf-0.91-1.5x.src.rpm -
Red Hat Inc. 5.2 sparc xpdf-0.91-1.5x.sparc.rpm
ftp://updates.redhat.com/5.2/sparc/xpdf-0.91-1.5x.sparc.rpm -
Red Hat Inc. 6.2 alpha xpdf-0.91-1.6x.alpha.rpm
ftp://updates.redhat.com/6.2/alpha/xpdf-0.91-1.6x.alpha.rpm -
Red Hat Inc. 6.2 i386 xpdf-0.91-1.6x.i386.rpm
ftp://updates.redhat.com/6.2/i386/xpdf-0.91-1.6x.i386.rpm -
Red Hat Inc. 6.2 source xpdf-0.91-1.6x.src.rpm
ftp://updates.redhat.com/6.2/SRPMS/xpdf-0.91-1.6x.src.rpm -
Red Hat Inc. 6.2 sparc xpdf-0.91-1.6x.sparc.rpm
ftp://updates.redhat.com/6.2/sparc/xpdf-0.91-1.6x.sparc.rpm -
Xpdf Xpdf 0.91
ftp://ftp.foolabs.com/pub/xpdf/xpdf-0.91.tgz