xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URLs, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xpdf | Xpdf | 0.90 (including) | 0.90 (including) |