CVE-2009-0800
published 2009-04-23CVE-2009-0800: Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow…
PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.49%
91.9th percentile
Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
Affected
148 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.3.9 | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
KOffice vulnerabilities
vendor_ubuntu·2010-08-17·CVSS 4.3
CVE-2009-0165 [MEDIUM] KOffice vulnerabilities
Title: KOffice vulnerabilities
Summary: PDF import support has been disabled in KWord due to many security
vulnerabilities that could be used by an attacker to run programs as your
login.
Will Dormann, Alin Rad Pop, Braden Thomas, and Drew Yao discovered that the
Xpdf used in KOffice contained multiple security issues in its JBIG2
decoder. If a user or automated system were tricked into opening a crafted
PDF file, an attacker could cause a denial of service or execute arbitrary
code with privileges of the user invoking the program. (CVE-2009-0146,
CVE-2009-0147, CVE-2009-0166, CVE-2009-0799, CVE-2009-0800, CVE-2009-1179,
CVE-2009-1180, CVE-2009-1181)
It was discovered that the Xpdf used in KOffice contained multiple security
issues when parsing malformed PDF documents. If a user or auto
Red Hat
PDF JBIG2 multiple input validation flaws
vendor_redhat·2009-04-16·CVSS 6.8
CVE-2009-0800 [MEDIUM] CWE-20 PDF JBIG2 multiple input validation flaws
PDF JBIG2 multiple input validation flaws
Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
Ubuntu
poppler vulnerabilities
vendor_ubuntu·2009-04-16
CVE-2009-1187 poppler vulnerabilities
Title: poppler vulnerabilities
Summary: poppler vulnerabilities
Will Dormann, Alin Rad Pop, Braden Thomas, and Drew Yao discovered that
poppler contained multiple security issues in its JBIG2 decoder. If a user
or automated system were tricked into opening a crafted PDF file, an
attacker could cause a denial of service or execute arbitrary code with
privileges of the user invoking the program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2009-0800: poppler - Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earli...
vendor_debian·2009·CVSS 6.8
CVE-2009-0800 [MEDIUM] CVE-2009-0800: poppler - Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earli...
Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 0.10.6-1)
bullseye: resolved (fixed in 0.10.6-1)
forky: resolved (fixed in 0.10.6-1)
sid: resolved (fixed in 0.10.6-1)
trixie: resolved (fixed in 0.10.6-1)
GHSA
GHSA-x57h-fgf6-293f: Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3
ghsa_unreviewed·2022-05-02
CVE-2009-0800 [MEDIUM] CWE-20 GHSA-x57h-fgf6-293f: Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3
Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
OSV
CVE-2009-0800: Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3
osv·2009-04-23·CVSS 6.8
CVE-2009-0800 [MEDIUM] CVE-2009-0800: Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3
Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F10]
bugzilla·2009-04-21·CVSS 4.3
CVE-2009-0146 [MEDIUM] CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F10]
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F10]
F10 tracking bug: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes in the 'blocks' bugs.
NOTE THIS ISSUE IS CURRENTLY EMBARGOED, DO NOT MAKE PUBLIC COMMITS OR COMMENTS ABOUT THIS ISSUE.
[bug automatically created by: add-tracking-bugs]
Discussion:
Fixed upstream in 0.10.6.
---
poppler-0.8.7-6.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/poppler-0.8.7-6.fc10
---
poppler-0.8.7-6.fc10 has been pushed to the Fedora 10 stable repository. If problems still persi
Bugzilla
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F11]
bugzilla·2009-04-21·CVSS 4.3
CVE-2009-0146 [MEDIUM] CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F11]
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F11]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes in the 'blocks' bugs.
NOTE THIS ISSUE IS CURRENTLY EMBARGOED, DO NOT MAKE PUBLIC COMMITS OR COMMENTS ABOUT THIS ISSUE.
[bug automatically created by: add-tracking-bugs]
Discussion:
Fixed upstream in 0.10.6.
---
Affects F11 too, but there's no 11 in version list in BZ yet.
---
This bug appears to have been reported against 'rawhide' during the Fedora 11 development cycle.
Changing version to '11'.
More information and reason for thi
Bugzilla
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F9]
bugzilla·2009-04-21·CVSS 4.3
CVE-2009-0146 [MEDIUM] CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F9]
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes in the 'blocks' bugs.
NOTE THIS ISSUE IS CURRENTLY EMBARGOED, DO NOT MAKE PUBLIC COMMITS OR COMMENTS ABOUT THIS ISSUE.
[bug automatically created by: add-tracking-bugs]
Discussion:
Fixed upstream in 0.10.6.
---
This message is a reminder that Fedora 9 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 9. It is Fedora's policy to close all
bug reports from releases
Bugzilla
CVE-2009-1338 kernel: 'kill sig -1' must only apply to caller's pid namespace
bugzilla·2009-04-16·CVSS 4.6
CVE-2009-1338 [MEDIUM] CVE-2009-1338 kernel: 'kill sig -1' must only apply to caller's pid namespace
CVE-2009-1338 kernel: 'kill sig -1' must only apply to caller's pid namespace
Description of problem:
Currently "kill -1" kills processes in all namespaces and breaks the
isolation of namespaces. Use "task_pid_vnr() > 1" to check since task_pid_vnr() returns 0 if process is outside the caller's namespace.
Upstream patch: http://git.kernel.org/linus/d25141a818383b3c3b09f065698c544a7a0ec6e7
Discussion:
Created attachment 339796
Upstream patch
---
PID namespaces is merged in 2.6.24. http://lwn.net/Articles/259217/
---
Created attachment 339815
Patch for mrg-1
---
(In reply to comment #12)
> We might need this patch too:
> commit 44c4e1b2581f7273ab14ef30b6430618801c57b1
> Author: Eric W. Biederman
> Date: Fri Feb 8 04:19:15 2008 -0800
>
> pid: Extend/Fix pid_vnr
Together with this p
Bugzilla
CVE-2009-0800 PDF JBIG2 multiple input validation flaws
bugzilla·2009-04-15·CVSS 6.8
CVE-2009-0800 [MEDIUM] CVE-2009-0800 PDF JBIG2 multiple input validation flaws
CVE-2009-0800 PDF JBIG2 multiple input validation flaws
Multiple input validation flaws were discovered in xpdf's JBIG2 decoder.
These flaws could lead to arbitrary code execute with the permissions of
the user running xpdf.
Will Dormann of the CERT/CC created the extensive testsuite for the JBIG2
decoder in various PDF libraries that found this flaw.
Acknowledgements:
Red Hat would like to thank Will Dormann of the CERT/CC for responsibly
reporting these flaws.
Discussion:
Embargo has been lifted.
---
xpdf-3.02-13.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/xpdf-3.02-13.fc9
---
xpdf-3.02-13.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/xpdf-3.02-13.fc10
---
xpdf-3.02-13.fc9 has been pushe
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://poppler.freedesktop.org/releases.htmlhttp://rhn.redhat.com/errata/RHSA-2009-0458.htmlhttp://secunia.com/advisories/34291http://secunia.com/advisories/34481http://secunia.com/advisories/34746http://secunia.com/advisories/34755http://secunia.com/advisories/34756http://secunia.com/advisories/34852http://secunia.com/advisories/34959http://secunia.com/advisories/34963http://secunia.com/advisories/34991http://secunia.com/advisories/35037http://secunia.com/advisories/35064http://secunia.com/advisories/35065http://secunia.com/advisories/35618http://secunia.com/advisories/35685http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.578477http://www.debian.org/security/2009/dsa-1790http://www.debian.org/security/2009/dsa-1793http://www.kb.cert.org/vuls/id/196617http://www.mandriva.com/security/advisories?name=MDVSA-2009:101http://www.mandriva.com/security/advisories?name=MDVSA-2010:087http://www.mandriva.com/security/advisories?name=MDVSA-2011:175http://www.redhat.com/support/errata/RHSA-2009-0429.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0430.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0431.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0480.htmlhttp://www.securityfocus.com/bid/34568http://www.securitytracker.com/id?1022073http://www.vupen.com/english/advisories/2009/1065http://www.vupen.com/english/advisories/2009/1066http://www.vupen.com/english/advisories/2009/1076http://www.vupen.com/english/advisories/2009/1077http://www.vupen.com/english/advisories/2010/1040https://bugzilla.redhat.com/show_bug.cgi?id=495887https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11323https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://poppler.freedesktop.org/releases.htmlhttp://rhn.redhat.com/errata/RHSA-2009-0458.htmlhttp://secunia.com/advisories/34291http://secunia.com/advisories/34481http://secunia.com/advisories/34746http://secunia.com/advisories/34755http://secunia.com/advisories/34756http://secunia.com/advisories/34852http://secunia.com/advisories/34959http://secunia.com/advisories/34963http://secunia.com/advisories/34991http://secunia.com/advisories/35037http://secunia.com/advisories/35064http://secunia.com/advisories/35065http://secunia.com/advisories/35618http://secunia.com/advisories/35685http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.578477http://www.debian.org/security/2009/dsa-1790http://www.debian.org/security/2009/dsa-1793http://www.kb.cert.org/vuls/id/196617http://www.mandriva.com/security/advisories?name=MDVSA-2009:101http://www.mandriva.com/security/advisories?name=MDVSA-2010:087http://www.mandriva.com/security/advisories?name=MDVSA-2011:175http://www.redhat.com/support/errata/RHSA-2009-0429.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0430.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0431.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0480.htmlhttp://www.securityfocus.com/bid/34568http://www.securitytracker.com/id?1022073http://www.vupen.com/english/advisories/2009/1065http://www.vupen.com/english/advisories/2009/1066http://www.vupen.com/english/advisories/2009/1076http://www.vupen.com/english/advisories/2009/1077http://www.vupen.com/english/advisories/2010/1040https://bugzilla.redhat.com/show_bug.cgi?id=495887https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11323https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html
2009-04-23
Published