CVE-2009-1180

CWE-39912 documents8 sources
Severity
6.8MEDIUM
EPSS
8.8%
top 7.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 23
Latest updateMay 2

Description

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages6 packages

Debianxpdf< 3.02-1.4+lenny1+3
Debianpoppler< 0.10.6-1+3
NVDapple/cups1.3.9+55
NVDpoppler/poppler0.10.5+47

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xx2p-3xq8-p2xm: The JBIG2 decoder in Xpdf 32022-05-02
OSV
CVE-2009-1180: The JBIG2 decoder in Xpdf 32009-04-23
CVEList
CVE-2009-1180: The JBIG2 decoder in Xpdf 32009-04-23

📋Vendor Advisories

4
Ubuntu
KOffice vulnerabilities2010-08-17
Ubuntu
poppler vulnerabilities2009-04-16
Red Hat
PDF JBIG2 invalid free()2009-04-16
Debian
CVE-2009-1180: poppler - The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler b...2009

💬Community

4
Bugzilla
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F10]2009-04-21
Bugzilla
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F11]2009-04-21
Bugzilla
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F9]2009-04-21
Bugzilla
CVE-2009-1180 PDF JBIG2 invalid free()2009-04-15
CVE-2009-1180 (MEDIUM CVSS 6.8) | The JBIG2 decoder in Xpdf 3.02pl2 a | cvebase.io