CVE-2009-0195
published 2009-04-23CVE-2009-0195: Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF…
PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.37%
91.8th percentile
Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | — | — |
| debian | xpdf | < xpdf 3.02-1.4+lenny1 (bookworm) | xpdf 3.02-1.4+lenny1 (bookworm) |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| glyphandcog | xpdfreader | <= 3.02 | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fvm9-xxrq-gwmc: Heap-based buffer overflow in Xpdf 3
ghsa_unreviewed·2022-05-02
CVE-2009-0195 [MEDIUM] CWE-119 GHSA-fvm9-xxrq-gwmc: Heap-based buffer overflow in Xpdf 3
Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.
OSV
CVE-2009-0195: Heap-based buffer overflow in Xpdf 3
osv·2009-04-23·CVSS 6.8
CVE-2009-0195 [MEDIUM] CVE-2009-0195: Heap-based buffer overflow in Xpdf 3
Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.
Ubuntu
KOffice vulnerabilities
vendor_ubuntu·2010-08-17·CVSS 4.3
CVE-2009-0165 [MEDIUM] KOffice vulnerabilities
Title: KOffice vulnerabilities
Summary: PDF import support has been disabled in KWord due to many security
vulnerabilities that could be used by an attacker to run programs as your
login.
Will Dormann, Alin Rad Pop, Braden Thomas, and Drew Yao discovered that the
Xpdf used in KOffice contained multiple security issues in its JBIG2
decoder. If a user or automated system were tricked into opening a crafted
PDF file, an attacker could cause a denial of service or execute arbitrary
code with privileges of the user invoking the program. (CVE-2009-0146,
CVE-2009-0147, CVE-2009-0166, CVE-2009-0799, CVE-2009-0800, CVE-2009-1179,
CVE-2009-1180, CVE-2009-1181)
It was discovered that the Xpdf used in KOffice contained multiple security
issues when parsing malformed PDF documents. If a user or auto
Red Hat
xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)
vendor_redhat·2009-04-16·CVSS 4.3
CVE-2009-0146 [MEDIUM] xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)
xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)
Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.
Red Hat
xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)
vendor_redhat·2009-04-16·CVSS 6.8
CVE-2009-0195 [MEDIUM] xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)
xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)
Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.
Debian
CVE-2009-0195: xpdf - Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably...
vendor_debian·2009·CVSS 6.8
CVE-2009-0195 [MEDIUM] CVE-2009-0195: xpdf - Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably...
Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.
Scope: local
bookworm: resolved (fixed in 3.02-1.4+lenny1)
bullseye: resolved (fixed in 3.02-1.4+lenny1)
forky: resolved (fixed in 3.02-1.4+lenny1)
sid: resolved (fixed in 3.02-1.4+lenny1)
trixie: resolved (fixed in 3.02-1.4+lenny1)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2009-0458.htmlhttp://secunia.com/advisories/34291http://secunia.com/advisories/34481http://secunia.com/advisories/34756http://secunia.com/advisories/34963http://secunia.com/advisories/35064http://secunia.com/secunia_research/2009-17/http://secunia.com/secunia_research/2009-18/http://www.mandriva.com/security/advisories?name=MDVSA-2010:087http://www.redhat.com/support/errata/RHSA-2009-0480.htmlhttp://www.securityfocus.com/archive/1/502759/100/0/threadedhttp://www.securityfocus.com/archive/1/502762/100/0/threadedhttp://www.securityfocus.com/bid/34791http://www.vupen.com/english/advisories/2010/1040https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10076http://rhn.redhat.com/errata/RHSA-2009-0458.htmlhttp://secunia.com/advisories/34291http://secunia.com/advisories/34481http://secunia.com/advisories/34756http://secunia.com/advisories/34963http://secunia.com/advisories/35064http://secunia.com/secunia_research/2009-17/http://secunia.com/secunia_research/2009-18/http://www.mandriva.com/security/advisories?name=MDVSA-2010:087http://www.redhat.com/support/errata/RHSA-2009-0480.htmlhttp://www.securityfocus.com/archive/1/502759/100/0/threadedhttp://www.securityfocus.com/archive/1/502762/100/0/threadedhttp://www.securityfocus.com/bid/34791http://www.vupen.com/english/advisories/2010/1040https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10076
2009-04-23
Published