Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-1693

Опубликовано: 18 апр. 2008
Источник: debian
EPSS Низкий

Описание

The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xpdffixed3.02package
popplerfixed0.6.4-1package
kdegraphicsnot-affectedpackage
texlive-binnot-affectedpackage
texlive-basenot-affectedpackage
swftoolsnot-affectedpackage

Примечания

  • see GfxFont.cc GfxFont::readEmbFontFile, line 362 checks if the font file is

  • a stream or not. Anyone knows a fixed version?

EPSS

Процентиль: 91%
0.06879
Низкий

Связанные уязвимости

ubuntu
около 17 лет назад

The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.

redhat
около 17 лет назад

The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.

nvd
около 17 лет назад

The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.

github
около 3 лет назад

The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.

oracle-oval
около 17 лет назад

ELSA-2008-0239: poppler security update (IMPORTANT)

EPSS

Процентиль: 91%
0.06879
Низкий