Lucene search

K
cveMitreCVE-2009-1144
HistoryApr 09, 2009 - 3:08 p.m.

CVE-2009-1144

2009-04-0915:08:35
CWE-94
mitre
web.nvd.nist.gov
35
cve-2009-1144
xpdf
gentoo
vulnerability
privilege escalation
poppler library

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

5.1%

Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEM_XPDFRC macro in a Gentoo build process that uses the poppler library.

Affected configurations

Nvd
Node
foolabsxpdfMatch0.5a
OR
foolabsxpdfMatch0.7a
OR
foolabsxpdfMatch0.91a
OR
foolabsxpdfMatch0.91b
OR
foolabsxpdfMatch0.91c
OR
foolabsxpdfMatch0.92a
OR
foolabsxpdfMatch0.92b
OR
foolabsxpdfMatch0.92c
OR
foolabsxpdfMatch0.92d
OR
foolabsxpdfMatch0.92e
OR
foolabsxpdfMatch0.93a
OR
foolabsxpdfMatch0.93b
OR
foolabsxpdfMatch0.93c
OR
foolabsxpdfMatch1.00a
OR
glyphandcogxpdfreaderRange3.02
OR
glyphandcogxpdfreaderMatch0.2
OR
glyphandcogxpdfreaderMatch0.3
OR
glyphandcogxpdfreaderMatch0.4
OR
glyphandcogxpdfreaderMatch0.5
OR
glyphandcogxpdfreaderMatch0.6
OR
glyphandcogxpdfreaderMatch0.7
OR
glyphandcogxpdfreaderMatch0.80
OR
glyphandcogxpdfreaderMatch0.90
OR
glyphandcogxpdfreaderMatch0.91
OR
glyphandcogxpdfreaderMatch0.93
OR
glyphandcogxpdfreaderMatch1.00
OR
glyphandcogxpdfreaderMatch1.01
OR
glyphandcogxpdfreaderMatch2.00
OR
glyphandcogxpdfreaderMatch2.01
OR
glyphandcogxpdfreaderMatch2.02
OR
glyphandcogxpdfreaderMatch2.03
OR
glyphandcogxpdfreaderMatch3.00
AND
gentoogentoo_linux
VendorProductVersionCPE
foolabsxpdf0.5acpe:2.3:a:foolabs:xpdf:0.5a:*:*:*:*:*:*:*
foolabsxpdf0.7acpe:2.3:a:foolabs:xpdf:0.7a:*:*:*:*:*:*:*
foolabsxpdf0.91acpe:2.3:a:foolabs:xpdf:0.91a:*:*:*:*:*:*:*
foolabsxpdf0.91bcpe:2.3:a:foolabs:xpdf:0.91b:*:*:*:*:*:*:*
foolabsxpdf0.91ccpe:2.3:a:foolabs:xpdf:0.91c:*:*:*:*:*:*:*
foolabsxpdf0.92acpe:2.3:a:foolabs:xpdf:0.92a:*:*:*:*:*:*:*
foolabsxpdf0.92bcpe:2.3:a:foolabs:xpdf:0.92b:*:*:*:*:*:*:*
foolabsxpdf0.92ccpe:2.3:a:foolabs:xpdf:0.92c:*:*:*:*:*:*:*
foolabsxpdf0.92dcpe:2.3:a:foolabs:xpdf:0.92d:*:*:*:*:*:*:*
foolabsxpdf0.92ecpe:2.3:a:foolabs:xpdf:0.92e:*:*:*:*:*:*:*
Rows per page:
1-10 of 331

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

5.1%