cbcvebase.
CVE-2009-0791
published 2009-06-09

CVE-2009-0791: Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF…

PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.54%
92.0th percentile
Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1) Decrypt.cxx, (2) FoFiTrueType.cxx, (3) gmem.c, (4) JBIG2Stream.cxx, and (5) PSOutputDev.cxx in pdftops/. NOTE: the JBIG2Stream.cxx vector may overlap CVE-2009-1179.

Affected

61 ranges· showing 25
VendorProductVersion rangeFixed in
applecups
applecups
applecups
applecups>= 0 < 1.3.10-11.3.10-1
applecups>= 0 < 1.3.10-11.3.10-1
applecups>= 0 < 1.3.10-11.3.10-1
applecups>= 0 < 1.3.10-11.3.10-1
debiancups< cups 1.3.10-1 (bookworm)cups 1.3.10-1 (bookworm)
debianpoppler< poppler 0.12.2-1 (bookworm)poppler 0.12.2-1 (bookworm)
freedesktoppoppler>= 0 < 0.12.2-10.12.2-1
freedesktoppoppler>= 0 < 0.12.2-10.12.2-1
freedesktoppoppler>= 0 < 0.12.2-10.12.2-1
freedesktoppoppler>= 0 < 0.12.2-10.12.2-1
popplerpoppler<= 0.10.5
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler
popplerpoppler

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.