Multiple Linux Vendor Xpdf Embedded...

- AV AC AU C I A
发布: 2000-08-29
修订: 2025-04-13

When a user clicks a URL, xpdf 0.90 and earlier starts the viewer (netscape by default) but does not properly handle shell meta characters, making it possible for to embed malicious code within PDF files. As well, these versions create files in /tmp insecurely, raising the possibility of symbolic link attacks.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息