CVE-2009-0791
published 2009-06-09CVE-2009-0791: Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.54%
92.0th percentile
Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1) Decrypt.cxx, (2) FoFiTrueType.cxx, (3) gmem.c, (4) JBIG2Stream.cxx, and (5) PSOutputDev.cxx in pdftops/. NOTE: the JBIG2Stream.cxx vector may overlap CVE-2009-1179.
Affected
61 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | >= 0 < 1.3.10-1 | 1.3.10-1 |
| apple | cups | >= 0 < 1.3.10-1 | 1.3.10-1 |
| apple | cups | >= 0 < 1.3.10-1 | 1.3.10-1 |
| apple | cups | >= 0 < 1.3.10-1 | 1.3.10-1 |
| debian | cups | < cups 1.3.10-1 (bookworm) | cups 1.3.10-1 (bookworm) |
| debian | poppler | < poppler 0.12.2-1 (bookworm) | poppler 0.12.2-1 (bookworm) |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| poppler | poppler | <= 0.10.5 | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-89xf-5fpv-6xg6: Multiple integer overflows in Xpdf 2
ghsa_unreviewed·2022-05-02·CVSS 6.8
CVE-2009-0791 [MEDIUM] GHSA-89xf-5fpv-6xg6: Multiple integer overflows in Xpdf 2
Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1) Decrypt.cxx, (2) FoFiTrueType.cxx, (3) gmem.c, (4) JBIG2Stream.cxx, and (5) PSOutputDev.cxx in pdftops/. NOTE: the JBIG2Stream.cxx vector may overlap CVE-2009-1179.
GHSA
GHSA-52vw-r24f-727x: Multiple integer overflows in Poppler 0
ghsa_unreviewed·2022-05-02·CVSS 6.8
CVE-2009-3605 [MEDIUM] GHSA-52vw-r24f-727x: Multiple integer overflows in Poppler 0
Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, related to (1) glib/poppler-page.cc; (2) ArthurOutputDev.cc, (3) CairoOutputDev.cc, (4) GfxState.cc, (5) JBIG2Stream.cc, (6) PSOutputDev.cc, and (7) SplashOutputDev.cc in poppler/; and (8) SplashBitmap.cc, (9) Splash.cc, and (10) SplashFTFont.cc in splash/. NOTE: this may overlap CVE-2009-0791.
OSV
CVE-2009-3605: Multiple integer overflows in Poppler 0
osv·2009-11-02·CVSS 6.8
CVE-2009-3605 [MEDIUM] CVE-2009-3605: Multiple integer overflows in Poppler 0
Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, related to (1) glib/poppler-page.cc; (2) ArthurOutputDev.cc, (3) CairoOutputDev.cc, (4) GfxState.cc, (5) JBIG2Stream.cc, (6) PSOutputDev.cc, and (7) SplashOutputDev.cc in poppler/; and (8) SplashBitmap.cc, (9) Splash.cc, and (10) SplashFTFont.cc in splash/. NOTE: this may overlap CVE-2009-0791.
OSV
CVE-2009-0791: Multiple integer overflows in Xpdf 2
osv·2009-06-09·CVSS 6.8
CVE-2009-0791 [MEDIUM] CVE-2009-0791: Multiple integer overflows in Xpdf 2
Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1) Decrypt.cxx, (2) FoFiTrueType.cxx, (3) gmem.c, (4) JBIG2Stream.cxx, and (5) PSOutputDev.cxx in pdftops/. NOTE: the JBIG2Stream.cxx vector may overlap CVE-2009-1179.
Red Hat
xpdf: multiple integer overflows
vendor_redhat·2009-05-19·CVSS 6.8
CVE-2009-3605 [MEDIUM] CWE-190 xpdf: multiple integer overflows
xpdf: multiple integer overflows
Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, related to (1) glib/poppler-page.cc; (2) ArthurOutputDev.cc, (3) CairoOutputDev.cc, (4) GfxState.cc, (5) JBIG2Stream.cc, (6) PSOutputDev.cc, and (7) SplashOutputDev.cc in poppler/; and (8) SplashBitmap.cc, (9) Splash.cc, and (10) SplashFTFont.cc in splash/. NOTE: this may overlap CVE-2009-0791.
Red Hat
xpdf: multiple integer overflows
vendor_redhat·2009-05-19·CVSS 6.8
CVE-2009-0791 [MEDIUM] CWE-190 xpdf: multiple integer overflows
xpdf: multiple integer overflows
Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1) Decrypt.cxx, (2) FoFiTrueType.cxx, (3) gmem.c, (4) JBIG2Stream.cxx, and (5) PSOutputDev.cxx in pdftops/. NOTE: the JBIG2Stream.cxx vector may overlap CVE-2009-1179.
Debian
CVE-2009-3605: poppler - Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers ...
vendor_debian·2009·CVSS 6.8
CVE-2009-3605 [MEDIUM] CVE-2009-3605: poppler - Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers ...
Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, related to (1) glib/poppler-page.cc; (2) ArthurOutputDev.cc, (3) CairoOutputDev.cc, (4) GfxState.cc, (5) JBIG2Stream.cc, (6) PSOutputDev.cc, and (7) SplashOutputDev.cc in poppler/; and (8) SplashBitmap.cc, (9) Splash.cc, and (10) SplashFTFont.cc in splash/. NOTE: this may overlap CVE-2009-0791.
Scope: local
bookworm: resolved (fixed in 0.12.2-1)
bullseye: resolved (fixed in 0.12.2-1)
forky: resolved (fixed in 0.12.2-1)
sid: resolved (fixed in 0.12.2-1)
trixie: resolved (fixed in 0.12.2-1)
Debian
CVE-2009-0791: cups - Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the p...
vendor_debian·2009·CVSS 6.8
CVE-2009-0791 [MEDIUM] CVE-2009-0791: cups - Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the p...
Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1) Decrypt.cxx, (2) FoFiTrueType.cxx, (3) gmem.c, (4) JBIG2Stream.cxx, and (5) PSOutputDev.cxx in pdftops/. NOTE: the JBIG2Stream.cxx vector may overlap CVE-2009-1179.
Scope: local
bookworm: resolved (fixed in 1.3.10-1)
bullseye: resolved (fixed in 1.3.10-1)
forky: resolved (fixed in 1.3.10-1)
sid: resolved (fixed in 1.3.10-1)
trixie: resolved (fixed in 1.3.10-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-0791 CVE-2009-360{3,4,6,7,8,9} Multiple poppler vulnerabilities
bugzilla·2009-10-25·CVSS 6.8
CVE-2009-0791 [MEDIUM] CVE-2009-0791 CVE-2009-360{3,4,6,7,8,9} Multiple poppler vulnerabilities
CVE-2009-0791 CVE-2009-360{3,4,6,7,8,9} Multiple poppler vulnerabilities
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #526637: CVE-2009-3608 xpdf/poppler: integer overflow in ObjectStream::ObjectStream (oCERT-2009-016)
bug #526911: CVE-2009-3604 xpdf/poppler: Splash::drawImage integer overflow and missing allocation return value check
bug #526915: CVE-2009-3603 xpdf/poppler: SplashBitmap::SplashBitmap integer overflow
bug #526924: CVE-2009-3607 poppler: create_surface_from_thumbnail_data integer overflow
bug #526877: CVE-2009-3606 xpdf/popple
Bugzilla
CVE-2009-0791 xpdf: multiple integer overflows
bugzilla·2009-03-24·CVSS 6.8
CVE-2009-0791 [MEDIUM] CVE-2009-0791 xpdf: multiple integer overflows
CVE-2009-0791 xpdf: multiple integer overflows
The CUPS "pdftops" filter converts Portable Document Format (PDF) files into PostScript. It is based upon Xpdf and the CUPS imaging library.
Multiple integer overflows, leading to heap-based buffer overflows, were
found in the CUPS "pdftops" filter. An attacker could create a malicious
PDF file that would cause "pdftops" to crash or, potentially, execute
arbitrary code as the "lp" user if the file was printed.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Via RHSA-2009:1083 https://rhn.redhat.com/errata/RHSA-2009-1083.html
---
Patch for this issue fixes all cases where gmalloc is called with argument consisting of multiplication of multiple values (such as gmalloc
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://secunia.com/advisories/35340http://secunia.com/advisories/35685http://secunia.com/advisories/37023http://secunia.com/advisories/37028http://secunia.com/advisories/37037http://secunia.com/advisories/37043http://secunia.com/advisories/37077http://secunia.com/advisories/37079http://securitytracker.com/id?1022326http://www.mandriva.com/security/advisories?name=MDVSA-2009:334http://www.redhat.com/support/errata/RHSA-2009-1083.htmlhttp://www.securityfocus.com/bid/35195http://www.vupen.com/english/advisories/2009/1488http://www.vupen.com/english/advisories/2009/2928https://bugzilla.redhat.com/show_bug.cgi?id=491840https://exchange.xforce.ibmcloud.com/vulnerabilities/50941https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10534https://rhn.redhat.com/errata/RHSA-2009-1500.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1501.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1502.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1503.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1512.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://secunia.com/advisories/35340http://secunia.com/advisories/35685http://secunia.com/advisories/37023http://secunia.com/advisories/37028http://secunia.com/advisories/37037http://secunia.com/advisories/37043http://secunia.com/advisories/37077http://secunia.com/advisories/37079http://securitytracker.com/id?1022326http://www.mandriva.com/security/advisories?name=MDVSA-2009:334http://www.redhat.com/support/errata/RHSA-2009-1083.htmlhttp://www.securityfocus.com/bid/35195http://www.vupen.com/english/advisories/2009/1488http://www.vupen.com/english/advisories/2009/2928https://bugzilla.redhat.com/show_bug.cgi?id=491840https://exchange.xforce.ibmcloud.com/vulnerabilities/50941https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10534https://rhn.redhat.com/errata/RHSA-2009-1500.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1501.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1502.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1503.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1512.html
2009-06-09
Published