Execution Flaw in Poppler and Associated Applications
CVE-2008-1693

Currently unrated

Key Information:

Vendor

Poppler

Status
Vendor
CVE Published:
18 April 2008

What is CVE-2008-1693?

The CairoFont::create function in Poppler has a vulnerability that arises from improper handling of embedded fonts in PDF files. This flaw can potentially allow remote attackers to execute arbitrary code via a crafted font object, specifically due to the improper dereferencing of a function pointer associated with the font object type. Affected applications that utilize Poppler, such as Xpdf, Evince, ePDFview, and KWord, could be exploited if users open maliciously crafted PDF documents.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.