Vulnerability Details CVE-2009-1144
Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEM_XPDFRC macro in a Gentoo build process that uses the poppler library.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 27.1%
CVSS Severity
CVSS v2 Score 6.9
Products affected by CVE-2009-1144
-
cpe:2.3:a:foolabs:xpdf:0.5a
-
cpe:2.3:a:foolabs:xpdf:0.7a
-
cpe:2.3:a:foolabs:xpdf:0.91a
-
cpe:2.3:a:foolabs:xpdf:0.91b
-
cpe:2.3:a:foolabs:xpdf:0.91c
-
cpe:2.3:a:foolabs:xpdf:0.92a
-
cpe:2.3:a:foolabs:xpdf:0.92b
-
cpe:2.3:a:foolabs:xpdf:0.92c
-
cpe:2.3:a:foolabs:xpdf:0.92d
-
cpe:2.3:a:foolabs:xpdf:0.92e
-
cpe:2.3:a:foolabs:xpdf:0.93a
-
cpe:2.3:a:foolabs:xpdf:0.93b
-
cpe:2.3:a:foolabs:xpdf:0.93c
-
cpe:2.3:a:foolabs:xpdf:1.00a
-
cpe:2.3:a:glyphandcog:xpdfreader:0.2
-
cpe:2.3:a:glyphandcog:xpdfreader:0.3
-
cpe:2.3:a:glyphandcog:xpdfreader:0.4
-
cpe:2.3:a:glyphandcog:xpdfreader:0.5
-
cpe:2.3:a:glyphandcog:xpdfreader:0.6
-
cpe:2.3:a:glyphandcog:xpdfreader:0.7
-
cpe:2.3:a:glyphandcog:xpdfreader:0.80
-
cpe:2.3:a:glyphandcog:xpdfreader:0.90
-
cpe:2.3:a:glyphandcog:xpdfreader:0.91
-
cpe:2.3:a:glyphandcog:xpdfreader:0.92
-
cpe:2.3:a:glyphandcog:xpdfreader:0.93
-
cpe:2.3:a:glyphandcog:xpdfreader:1.00
-
cpe:2.3:a:glyphandcog:xpdfreader:1.01
-
cpe:2.3:a:glyphandcog:xpdfreader:2.00
-
cpe:2.3:a:glyphandcog:xpdfreader:2.01
-
cpe:2.3:a:glyphandcog:xpdfreader:2.02
-
cpe:2.3:a:glyphandcog:xpdfreader:2.03
-
cpe:2.3:a:glyphandcog:xpdfreader:3.00
-
cpe:2.3:a:glyphandcog:xpdfreader:3.01
-
cpe:2.3:a:glyphandcog:xpdfreader:3.02
-
cpe:2.3:o:gentoo:gentoo_linux:*