CVE-2009-0147
published 2009-04-23CVE-2009-0147: Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.58%
83.5th percentile
Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.
Affected
101 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.3.9 | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
KOffice vulnerabilities
vendor_ubuntu·2010-08-17·CVSS 4.3
CVE-2009-0165 [MEDIUM] KOffice vulnerabilities
Title: KOffice vulnerabilities
Summary: PDF import support has been disabled in KWord due to many security
vulnerabilities that could be used by an attacker to run programs as your
login.
Will Dormann, Alin Rad Pop, Braden Thomas, and Drew Yao discovered that the
Xpdf used in KOffice contained multiple security issues in its JBIG2
decoder. If a user or automated system were tricked into opening a crafted
PDF file, an attacker could cause a denial of service or execute arbitrary
code with privileges of the user invoking the program. (CVE-2009-0146,
CVE-2009-0147, CVE-2009-0166, CVE-2009-0799, CVE-2009-0800, CVE-2009-1179,
CVE-2009-1180, CVE-2009-1181)
It was discovered that the Xpdf used in KOffice contained multiple security
issues when parsing malformed PDF documents. If a user or auto
Red Hat
xpdf: Multiple integer overflows in JBIG2 decoder
vendor_redhat·2009-04-16·CVSS 4.3
CVE-2009-0147 [MEDIUM] CWE-190 xpdf: Multiple integer overflows in JBIG2 decoder
xpdf: Multiple integer overflows in JBIG2 decoder
Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.
Ubuntu
poppler vulnerabilities
vendor_ubuntu·2009-04-16
CVE-2009-1187 poppler vulnerabilities
Title: poppler vulnerabilities
Summary: poppler vulnerabilities
Will Dormann, Alin Rad Pop, Braden Thomas, and Drew Yao discovered that
poppler contained multiple security issues in its JBIG2 decoder. If a user
or automated system were tricked into opening a crafted PDF file, an
attacker could cause a denial of service or execute arbitrary code with
privileges of the user invoking the program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2009-0147: cups - Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUP...
vendor_debian·2009·CVSS 4.3
CVE-2009-0147 [MEDIUM] CVE-2009-0147: cups - Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUP...
Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-6336-f8r9-rhcv: Multiple integer overflows in the JBIG2 decoder in Xpdf 3
ghsa_unreviewed·2022-05-02
CVE-2009-0147 [MEDIUM] GHSA-6336-f8r9-rhcv: Multiple integer overflows in the JBIG2 decoder in Xpdf 3
Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.
OSV
CVE-2009-0147: Multiple integer overflows in the JBIG2 decoder in Xpdf 3
osv·2009-04-23·CVSS 4.3
CVE-2009-0147 [MEDIUM] CVE-2009-0147: Multiple integer overflows in the JBIG2 decoder in Xpdf 3
Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-4308 kernel: ext4: Avoid null pointer dereference when decoding EROFS w/o a journal
bugzilla·2009-12-14·CVSS 7.1
CVE-2009-4308 [HIGH] CVE-2009-4308 kernel: ext4: Avoid null pointer dereference when decoding EROFS w/o a journal
CVE-2009-4308 kernel: ext4: Avoid null pointer dereference when decoding EROFS w/o a journal
Description of problem:
ext4: Avoid null pointer dereference when decoding EROFS w/o a journal
We need to check to make sure a journal is present before checking the journal flags in ext4_decode_error().
Upstream commit:
http://git.kernel.org/linus/78f1ddbb498283c2445c11b0dfa666424c301803
Reference:
http://secunia.com/advisories/37658
Discussion:
Patch present on the current RHEL6 git tree
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0147 https://rhn.redhat.com/errata/RHSA-2010-0147.html
Bugzilla
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F10]
bugzilla·2009-04-21·CVSS 4.3
CVE-2009-0146 [MEDIUM] CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F10]
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F10]
F10 tracking bug: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes in the 'blocks' bugs.
NOTE THIS ISSUE IS CURRENTLY EMBARGOED, DO NOT MAKE PUBLIC COMMITS OR COMMENTS ABOUT THIS ISSUE.
[bug automatically created by: add-tracking-bugs]
Discussion:
Fixed upstream in 0.10.6.
---
poppler-0.8.7-6.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/poppler-0.8.7-6.fc10
---
poppler-0.8.7-6.fc10 has been pushed to the Fedora 10 stable repository. If problems still persi
Bugzilla
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F11]
bugzilla·2009-04-21·CVSS 4.3
CVE-2009-0146 [MEDIUM] CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F11]
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F11]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes in the 'blocks' bugs.
NOTE THIS ISSUE IS CURRENTLY EMBARGOED, DO NOT MAKE PUBLIC COMMITS OR COMMENTS ABOUT THIS ISSUE.
[bug automatically created by: add-tracking-bugs]
Discussion:
Fixed upstream in 0.10.6.
---
Affects F11 too, but there's no 11 in version list in BZ yet.
---
This bug appears to have been reported against 'rawhide' during the Fedora 11 development cycle.
Changing version to '11'.
More information and reason for thi
Bugzilla
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F9]
bugzilla·2009-04-21·CVSS 4.3
CVE-2009-0146 [MEDIUM] CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F9]
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes in the 'blocks' bugs.
NOTE THIS ISSUE IS CURRENTLY EMBARGOED, DO NOT MAKE PUBLIC COMMITS OR COMMENTS ABOUT THIS ISSUE.
[bug automatically created by: add-tracking-bugs]
Discussion:
Fixed upstream in 0.10.6.
---
This message is a reminder that Fedora 9 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 9. It is Fedora's policy to close all
bug reports from releases
Bugzilla
Multiple PDF flaws
bugzilla·2009-03-24·CVSS 4.3
CVE-2009-0146 [MEDIUM] Multiple PDF flaws
Multiple PDF flaws
Created attachment 336465
Proposed patch
CERT created a test archive of broken PDF files that focus on the JBIG2 image decoder contained in xpdf/poppler and variants.
Derek Noonburg created a patch that fixes all crashes the PDF archive caused.
The patch also fixes the issues CVE-2009-0146 CVE-2009-0147 CVE-2009-0166.
Discussion:
Created attachment 337048
updated patch from upstream
This is the updated patch from Derek.
---
Created attachment 337193
Updated upstream patch, converted to unified format
Same patch as in comment #6 above, just converted from context diff to a lot more readable unified diff.
Interdiff against the original patch in comment #0:
--- xpdf-3.02/xpdf/JBIG2Stream.cc
+++ xpdf-3.02/xpdf/JBIG2Stream.cc
@@ -805,6 +805,10 @@
Guint src0, src1,
Bugzilla
CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder
bugzilla·2009-03-17·CVSS 4.3
CVE-2009-0147 [MEDIUM] CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder
CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder
Multiple integer overflows and one integer signedness error were found
in the JBIG2 decoder. An attacker could use these flaws to cause a denial of service (application crash) via specially-crafted PDF file.
Acknowledgements:
Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product
Security team for responsibly reporting these flaws.
Discussion:
attachment 336465 has the updated patch that should be used for this issue.
---
Embargo has been lifted.
---
xpdf-3.02-13.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/xpdf-3.02-13.fc9
---
xpdf-3.02-13.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/xpdf-3.02-13.fc10
---
http://bugs.gentoo.org/show_bug.cgi?id=263028http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2009-0458.htmlhttp://secunia.com/advisories/34291http://secunia.com/advisories/34481http://secunia.com/advisories/34755http://secunia.com/advisories/34756http://secunia.com/advisories/34852http://secunia.com/advisories/34959http://secunia.com/advisories/34963http://secunia.com/advisories/34991http://secunia.com/advisories/35037http://secunia.com/advisories/35064http://secunia.com/advisories/35065http://secunia.com/advisories/35074http://secunia.com/advisories/35618http://secunia.com/advisories/35685http://security.gentoo.org/glsa/glsa-200904-20.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.578477http://support.apple.com/kb/HT3549http://support.apple.com/kb/HT3639http://wiki.rpath.com/Advisories:rPSA-2009-0059http://wiki.rpath.com/Advisories:rPSA-2009-0061http://www.debian.org/security/2009/dsa-1790http://www.debian.org/security/2009/dsa-1793http://www.mandriva.com/security/advisories?name=MDVSA-2009:101http://www.mandriva.com/security/advisories?name=MDVSA-2010:087http://www.redhat.com/support/errata/RHSA-2009-0429.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0430.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0431.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0480.htmlhttp://www.securityfocus.com/archive/1/502750/100/0/threadedhttp://www.securityfocus.com/archive/1/502761/100/0/threadedhttp://www.securityfocus.com/bid/34568http://www.securitytracker.com/id?1022073http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1065http://www.vupen.com/english/advisories/2009/1066http://www.vupen.com/english/advisories/2009/1077http://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2009/1621http://www.vupen.com/english/advisories/2010/1040https://bugzilla.redhat.com/show_bug.cgi?id=490614https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9941https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=263028http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2009-0458.htmlhttp://secunia.com/advisories/34291http://secunia.com/advisories/34481http://secunia.com/advisories/34755http://secunia.com/advisories/34756http://secunia.com/advisories/34852http://secunia.com/advisories/34959http://secunia.com/advisories/34963http://secunia.com/advisories/34991http://secunia.com/advisories/35037http://secunia.com/advisories/35064http://secunia.com/advisories/35065http://secunia.com/advisories/35074http://secunia.com/advisories/35618http://secunia.com/advisories/35685http://security.gentoo.org/glsa/glsa-200904-20.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.578477http://support.apple.com/kb/HT3549http://support.apple.com/kb/HT3639http://wiki.rpath.com/Advisories:rPSA-2009-0059http://wiki.rpath.com/Advisories:rPSA-2009-0061http://www.debian.org/security/2009/dsa-1790http://www.debian.org/security/2009/dsa-1793http://www.mandriva.com/security/advisories?name=MDVSA-2009:101http://www.mandriva.com/security/advisories?name=MDVSA-2010:087http://www.redhat.com/support/errata/RHSA-2009-0429.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0430.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0431.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0480.htmlhttp://www.securityfocus.com/archive/1/502750/100/0/threadedhttp://www.securityfocus.com/archive/1/502761/100/0/threadedhttp://www.securityfocus.com/bid/34568http://www.securitytracker.com/id?1022073http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1065http://www.vupen.com/english/advisories/2009/1066http://www.vupen.com/english/advisories/2009/1077http://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2009/1621http://www.vupen.com/english/advisories/2010/1040https://bugzilla.redhat.com/show_bug.cgi?id=490614https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9941https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html
+ 2 more references
2009-04-23
Published