CVE-2009-1144
Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEM_XPDFRC macro in a Gentoo build process…
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEM_XPDFRC macro in a Gentoo build process that uses the poppler library.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- foolabs/xpdf · glyphandcog/xpdfreader
- Source
- cve@mitre.org
References
- http://bugs.gentoo.org/show_bug.cgi?id=200023Vendor Advisory
- http://bugs.gentoo.org/show_bug.cgi?id=242930Vendor Advisory
- http://osvdb.org/53529
- http://secunia.com/advisories/34610Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200904-07.xml
- http://www.securityfocus.com/bid/34401
- http://bugs.gentoo.org/show_bug.cgi?id=200023Vendor Advisory
- http://bugs.gentoo.org/show_bug.cgi?id=242930Vendor Advisory
- http://osvdb.org/53529
- http://secunia.com/advisories/34610Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200904-07.xml
- http://www.securityfocus.com/bid/34401
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.