Calling Components Safely

Clicking on a hypertext link while viewing a PDF file shouldn’t be a security problem as long as you trust the viewer it invokes. But users of xpdf version 0.90 discovered that this assumption was an extremely bad one. When an xpdf user clicked on a hypertext link, xpdf started up a viewer (Netscape by default) and sent the URL to the viewer. So far, so good. But the xpdf developers decided to start up the viewer by using the system() call. That was the bad idea..

11 Comments

  1. 2004-12-27 11:47 pm
  2. 2004-12-28 12:31 am
  3. 2004-12-28 4:43 am
  4. 2004-12-28 5:38 pm
  5. 2004-12-28 5:56 pm
  6. 2004-12-28 8:17 pm
  7. 2004-12-28 9:27 pm
  8. 2004-12-28 11:41 pm
  9. 2004-12-29 5:58 pm
  10. 2004-12-29 10:28 pm
  11. 2005-01-01 10:49 am