Release date:
Updated on:
Affected Systems:
Poppler 0.24.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 63374
Poppler is a library for parsing PDF documents. Xpdf is an open source code viewer for Portable Document Format (PDF) files.
In utils versions earlier than version 0.24.3, attackers have a format string vulnerability that can be controlled by attackers. Attackers can exploit this vulnerability to execute arbitrary code in the affected application context.
<* Source: Pedro Ribeiro
Daniel Kahn Gillmor
Link: http://seclists.org/oss-sec/2013/q4/181
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
./Eclipseparate-f 1-l 1 apdffileapps" % x % n"
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Poppler
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://poppler.freedesktop.org/