Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-0756 — Poppler vulnerability

8 documents8 sources
Severity
5.0MEDIUMNVD
EPSS
14.0%
top 5.65%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMar 3
Latest updateMay 2

Description

The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and triggers an invalid memory dereference.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

â–¶Debianfreedesktop/poppler< 0.10.6-1+3
â–¶NVDpoppler/poppler0.10.3+33

🔴Vulnerability Details

3
GHSA
GHSA-fm5j-vjr3-jf4v: The JBIG2Stream::readSymbolDictSeg function in Poppler before 0↗2022-05-02
â–¶
CVEList
CVE-2009-0756: The JBIG2Stream::readSymbolDictSeg function in Poppler before 0↗2009-03-03
â–¶
OSV
CVE-2009-0756: The JBIG2Stream::readSymbolDictSeg function in Poppler before 0↗2009-03-03
â–¶

💥Exploits & PoCs

1
Exploit-DB
Poppler 0.10.3 - Denial of Service↗2009-02-12
â–¶

📋Vendor Advisories

2
Red Hat
poppler/evince: DoS via crafted PDF file↗2009-01-22
â–¶
Debian
CVE-2009-0756: poppler - The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remo...↗2009
â–¶

💬Community

1
Bugzilla
CVE-2009-0756 poppler/evince: DoS via crafted PDF file↗2009-03-03
â–¶
CVE-2009-0756 — Poppler vulnerability | cvebase