CVE-2009-0165
published 2009-04-23CVE-2009-0165: Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact…
PriorityP336critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.59%
88.1th percentile
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xpdf | < xpdf 3.02-1.4+lenny1 (bookworm) | xpdf 3.02-1.4+lenny1 (bookworm) |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| glyphandcog | xpdfreader | <= 3.02 | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0LOW
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qx4p-wc3g-wr66: Integer overflow in the JBIG2 decoder in Xpdf 3
ghsa_unreviewed·2022-05-02
CVE-2009-0165 [HIGH] GHSA-qx4p-wc3g-wr66: Integer overflow in the JBIG2 decoder in Xpdf 3
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."
OSV
CVE-2009-0165: Integer overflow in the JBIG2 decoder in Xpdf 3
osv·2009-04-23·CVSS 10.0
CVE-2009-0165 [CRITICAL] CVE-2009-0165: Integer overflow in the JBIG2 decoder in Xpdf 3
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."
Ubuntu
KOffice vulnerabilities
vendor_ubuntu·2010-08-17·CVSS 4.3
CVE-2009-0165 [MEDIUM] KOffice vulnerabilities
Title: KOffice vulnerabilities
Summary: PDF import support has been disabled in KWord due to many security
vulnerabilities that could be used by an attacker to run programs as your
login.
Will Dormann, Alin Rad Pop, Braden Thomas, and Drew Yao discovered that the
Xpdf used in KOffice contained multiple security issues in its JBIG2
decoder. If a user or automated system were tricked into opening a crafted
PDF file, an attacker could cause a denial of service or execute arbitrary
code with privileges of the user invoking the program. (CVE-2009-0146,
CVE-2009-0147, CVE-2009-0166, CVE-2009-0799, CVE-2009-0800, CVE-2009-1179,
CVE-2009-1180, CVE-2009-1181)
It was discovered that the Xpdf used in KOffice contained multiple security
issues when parsing malformed PDF documents. If a user or auto
Debian
CVE-2009-0165: xpdf - Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Po...
vendor_debian·2009·CVSS 10.0
CVE-2009-0165 [CRITICAL] CVE-2009-0165: xpdf - Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Po...
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."
Scope: local
bookworm: resolved (fixed in 3.02-1.4+lenny1)
bullseye: resolved (fixed in 3.02-1.4+lenny1)
forky: resolved (fixed in 3.02-1.4+lenny1)
sid: resolved (fixed in 3.02-1.4+lenny1)
trixie: resolved (fixed in 3.02-1.4+lenny1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.gentoo.org/show_bug.cgi?id=263028http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://secunia.com/advisories/34852http://secunia.com/advisories/34959http://secunia.com/advisories/34991http://secunia.com/advisories/35037http://secunia.com/advisories/35065http://secunia.com/advisories/35074http://secunia.com/advisories/35685http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.578477http://support.apple.com/kb/HT3549http://support.apple.com/kb/HT3639http://www.debian.org/security/2009/dsa-1790http://www.debian.org/security/2009/dsa-1793http://www.mandriva.com/security/advisories?name=MDVSA-2009:101http://www.securityfocus.com/bid/34568http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2009/1621https://exchange.xforce.ibmcloud.com/vulnerabilities/50377http://bugs.gentoo.org/show_bug.cgi?id=263028http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://secunia.com/advisories/34852http://secunia.com/advisories/34959http://secunia.com/advisories/34991http://secunia.com/advisories/35037http://secunia.com/advisories/35065http://secunia.com/advisories/35074http://secunia.com/advisories/35685http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.578477http://support.apple.com/kb/HT3549http://support.apple.com/kb/HT3639http://www.debian.org/security/2009/dsa-1790http://www.debian.org/security/2009/dsa-1793http://www.mandriva.com/security/advisories?name=MDVSA-2009:101http://www.securityfocus.com/bid/34568http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2009/1621https://exchange.xforce.ibmcloud.com/vulnerabilities/50377
2009-04-23
Published