CVE-2009-1144 is an untrusted search path vulnerability affecting the Gentoo package of Xpdf prior to version 3.02-r2. This flaw allows local attackers to gain privileges by tricking the application into executing a malicious xpdfrc file from the current working directory, stemming from an unset SYSTEM_XPDFRC macro during the Gentoo build process. With a CVSS score of 6.9, this vulnerability is of medium severity, requiring local access and moderate attack complexity, but potentially leading to complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.5aCPE matchmatch criteria | cpe:2.3:a:foolabs:xpdf:0.5a:*:*:*:*:*:*:* | ||
0.7aCPE matchmatch criteria | cpe:2.3:a:foolabs:xpdf:0.7a:*:*:*:*:*:*:* | ||
0.91aCPE matchmatch criteria | cpe:2.3:a:foolabs:xpdf:0.91a:*:*:*:*:*:*:* | ||
0.91bCPE matchmatch criteria | cpe:2.3:a:foolabs:xpdf:0.91b:*:*:*:*:*:*:* | ||
0.91cCPE matchmatch criteria | cpe:2.3:a:foolabs:xpdf:0.91c:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.