CVE-2003-0434
published 2003-07-24CVE-2003-0434: Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an…
PriorityP350high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
40.94%
98.5th percentile
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| debian | xpdf | < xpdf 2.02pl1-1 (bookworm) | xpdf 2.02pl1-1 (bookworm) |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux_corporate_server | — | — |
| redhat | enterprise_linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux_advanced_workstation | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | >= 0 < 2.02pl1-1 | 2.02pl1-1 |
| xpdf | xpdf | >= 0 < 2.02pl1-1 | 2.02pl1-1 |
| xpdf | xpdf | >= 0 < 2.02pl1-1 | 2.02pl1-1 |
| xpdf | xpdf | >= 0 < 2.02pl1-1 | 2.02pl1-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2003-06-13·CVSS 7.5
CVE-2003-0434 [HIGH] security flaw
security flaw
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
Debian
CVE-2003-0434: xpdf - Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow rem...
vendor_debian·2003·CVSS 7.5
CVE-2003-0434 [HIGH] CVE-2003-0434: xpdf - Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow rem...
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
Scope: local
bookworm: resolved (fixed in 2.02pl1-1)
bullseye: resolved (fixed in 2.02pl1-1)
forky: resolved (fixed in 2.02pl1-1)
sid: resolved (fixed in 2.02pl1-1)
trixie: resolved (fixed in 2.02pl1-1)
GHSA
GHSA-857w-p662-mpmp: Various PDF viewers including (1) Adobe Acrobat 5
ghsa_unreviewed·2022-04-29
CVE-2003-0434 [HIGH] GHSA-857w-p662-mpmp: Various PDF viewers including (1) Adobe Acrobat 5
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
OSV
CVE-2003-0434: Various PDF viewers including (1) Adobe Acrobat 5
osv·2003-07-24·CVSS 7.5
CVE-2003-0434 [HIGH] CVE-2003-0434: Various PDF viewers including (1) Adobe Acrobat 5
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
No detection rules found.
http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005719.htmlhttp://marc.info/?l=bugtraq&m=105777963019186&w=2http://secunia.com/advisories/9037http://secunia.com/advisories/9038http://www.kb.cert.org/vuls/id/200132http://www.mandriva.com/security/advisories?name=MDKSA-2003:071http://www.redhat.com/support/errata/RHSA-2003-196.htmlhttp://www.redhat.com/support/errata/RHSA-2003-197.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A664http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005719.htmlhttp://marc.info/?l=bugtraq&m=105777963019186&w=2http://secunia.com/advisories/9037http://secunia.com/advisories/9038http://www.kb.cert.org/vuls/id/200132http://www.mandriva.com/security/advisories?name=MDKSA-2003:071http://www.redhat.com/support/errata/RHSA-2003-196.htmlhttp://www.redhat.com/support/errata/RHSA-2003-197.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A664
2003-07-24
Published