CVE-2009-1188
published 2009-04-23CVE-2009-1188: Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before…
PriorityP432medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
7.23%
93.6th percentile
Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
Affected
78 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | poppler | < poppler 0.10.6-1 (bookworm) | poppler 0.10.6-1 (bookworm) |
| debian | poppler | < poppler 0.12.2-1 (bookworm) | poppler 0.12.2-1 (bookworm) |
| debian | xpdf | < poppler 0.10.6-1 (bookworm) | poppler 0.10.6-1 (bookworm) |
| debian | xpdf | < poppler 0.12.2-1 (bookworm) | poppler 0.12.2-1 (bookworm) |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| freedesktop | poppler | >= 0 < 0.10.6-1 | 0.10.6-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.10.6-1 | 0.10.6-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.10.6-1 | 0.10.6-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.10.6-1 | 0.10.6-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| poppler | poppler | <= 0.10.5 | — |
| poppler | poppler | <= 0.12.0 | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xpdf/poppler: SplashBitmap:: SplashBitmap integer overflow
vendor_redhat·2009-10-14·CVSS 5.0
CVE-2009-3603 [MEDIUM] CWE-190 xpdf/poppler: SplashBitmap:: SplashBitmap integer overflow
xpdf/poppler: SplashBitmap:: SplashBitmap integer overflow
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.
Red Hat
xpdf/poppler: SplashBitmap integer overflow
vendor_redhat·2009-04-16·CVSS 5.0
CVE-2009-1188 [MEDIUM] CWE-190 xpdf/poppler: SplashBitmap integer overflow
xpdf/poppler: SplashBitmap integer overflow
Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
Ubuntu
poppler vulnerabilities
vendor_ubuntu·2009-04-16
CVE-2009-1187 poppler vulnerabilities
Title: poppler vulnerabilities
Summary: poppler vulnerabilities
Will Dormann, Alin Rad Pop, Braden Thomas, and Drew Yao discovered that
poppler contained multiple security issues in its JBIG2 decoder. If a user
or automated system were tricked into opening a crafted PDF file, an
attacker could cause a denial of service or execute arbitrary code with
privileges of the user invoking the program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2009-1188: poppler - Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap...
vendor_debian·2009·CVSS 5.0
CVE-2009-1188 [MEDIUM] CVE-2009-1188: poppler - Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap...
Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
Scope: local
bookworm: resolved (fixed in 0.10.6-1)
bullseye: resolved (fixed in 0.10.6-1)
forky: resolved (fixed in 0.10.6-1)
sid: resolved (fixed in 0.10.6-1)
trixie: resolved (fixed in 0.10.6-1)
Debian
CVE-2009-3603: poppler - Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3...
vendor_debian·2009·CVSS 5.0
CVE-2009-3603 [MEDIUM] CVE-2009-3603: poppler - Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3...
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.
Scope: local
bookworm: resolved (fixed in 0.12.2-1)
bullseye: resolved (fixed in 0.12.2-1)
forky: resolved (fixed in 0.12.2-1)
sid: resolved (fixed in 0.12.2-1)
trixie: resolved (fixed in 0.12.2-1)
GHSA
GHSA-2mhp-j72r-j69f: Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3
ghsa_unreviewed·2022-05-03·CVSS 5.0
CVE-2009-3603 [MEDIUM] GHSA-2mhp-j72r-j69f: Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.
GHSA
GHSA-33p4-7h6v-86r2: Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap
ghsa_unreviewed·2022-05-02
CVE-2009-1188 [MEDIUM] GHSA-33p4-7h6v-86r2: Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap
Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
OSV
CVE-2009-3603: Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3
osv·2009-10-21·CVSS 5.0
CVE-2009-3603 [MEDIUM] CVE-2009-3603: Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.
OSV
CVE-2009-1188: Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap
osv·2009-04-23·CVSS 5.0
CVE-2009-1188 [MEDIUM] CVE-2009-1188: Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap
Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3603 xpdf/poppler: SplashBitmap::SplashBitmap integer overflow
bugzilla·2009-10-02·CVSS 5.0
CVE-2009-3603 [MEDIUM] CVE-2009-3603 xpdf/poppler: SplashBitmap::SplashBitmap integer overflow
CVE-2009-3603 xpdf/poppler: SplashBitmap::SplashBitmap integer overflow
Integer overflow was discovered in SplashBitmap::SplashBitmap when computing memory allocation requirements. This issue was previously reported as CVE-2009-1188 / bug #495907 and addressed in poppler via gmalloc -> gmallocn change via:
http://cgit.freedesktop.org/poppler/poppler/commit/?id=9cf2325fb2
However, such fix is not sufficient, as overflow can occur even during rowSize calculation.
Splash output device is not present in xpdf 2.x, it's also not in the xpdf code embedded in CUPS or tetex.
Discussion:
Created attachment 363486
xpdf upstream patch from Derek B. Noonburg
---
xpdf is fixed now for the CVE-2009-1188/CVE-2009-3603 in xpdf-3.02pl4:
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl4.patch
https://bugzil
Bugzilla
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F10]
bugzilla·2009-04-21·CVSS 4.3
CVE-2009-0146 [MEDIUM] CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F10]
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F10]
F10 tracking bug: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes in the 'blocks' bugs.
NOTE THIS ISSUE IS CURRENTLY EMBARGOED, DO NOT MAKE PUBLIC COMMITS OR COMMENTS ABOUT THIS ISSUE.
[bug automatically created by: add-tracking-bugs]
Discussion:
Fixed upstream in 0.10.6.
---
poppler-0.8.7-6.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/poppler-0.8.7-6.fc10
---
poppler-0.8.7-6.fc10 has been pushed to the Fedora 10 stable repository. If problems still persi
Bugzilla
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F11]
bugzilla·2009-04-21·CVSS 4.3
CVE-2009-0146 [MEDIUM] CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F11]
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F11]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes in the 'blocks' bugs.
NOTE THIS ISSUE IS CURRENTLY EMBARGOED, DO NOT MAKE PUBLIC COMMITS OR COMMENTS ABOUT THIS ISSUE.
[bug automatically created by: add-tracking-bugs]
Discussion:
Fixed upstream in 0.10.6.
---
Affects F11 too, but there's no 11 in version list in BZ yet.
---
This bug appears to have been reported against 'rawhide' during the Fedora 11 development cycle.
Changing version to '11'.
More information and reason for thi
Bugzilla
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F9]
bugzilla·2009-04-21·CVSS 4.3
CVE-2009-0146 [MEDIUM] CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F9]
CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 poppler various flaws [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes in the 'blocks' bugs.
NOTE THIS ISSUE IS CURRENTLY EMBARGOED, DO NOT MAKE PUBLIC COMMITS OR COMMENTS ABOUT THIS ISSUE.
[bug automatically created by: add-tracking-bugs]
Discussion:
Fixed upstream in 0.10.6.
---
This message is a reminder that Fedora 9 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 9. It is Fedora's policy to close all
bug reports from releases
Bugzilla
CVE-2009-1188 xpdf/poppler: SplashBitmap integer overflow
bugzilla·2009-04-15·CVSS 5.0
CVE-2009-1188 [MEDIUM] CVE-2009-1188 xpdf/poppler: SplashBitmap integer overflow
CVE-2009-1188 xpdf/poppler: SplashBitmap integer overflow
An integer overflow was found in poppler's SplashBitmap::SplashBitmap
method. A malicious PDF file could cause poppler to execute with
permissions of the user calling the library.
Will Dormann of the CERT/CC created the extensive testsuite for the JBIG2
decoder in various PDF libraries that found this flaw.
Acknowledgements:
Red Hat would like to thank Will Dormann of the CERT/CC for responsibly
reporting this flaw.
Discussion:
CVE-2009-1188:
Integer overflow in the JBIG2 decoding feature in Poppler before
0.10.6 allows remote attackers to cause a denial of service (crash)
and possibly execute arbitrary code via vectors related to
SplashBitmap (splash/SplashBitmap.cc).
---
This issue has been addressed in following products:
http://bugs.gentoo.org/show_bug.cgi?id=263028#c16http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035340.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035399.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035408.htmlhttp://poppler.freedesktop.org/releases.htmlhttp://secunia.com/advisories/34746http://secunia.com/advisories/35064http://secunia.com/advisories/35618http://secunia.com/advisories/37028http://secunia.com/advisories/37037http://secunia.com/advisories/37043http://secunia.com/advisories/37053http://secunia.com/advisories/37077http://secunia.com/advisories/37079http://secunia.com/advisories/39327http://secunia.com/advisories/39938http://wiki.rpath.com/Advisories:rPSA-2009-0059http://www.debian.org/security/2010/dsa-2028http://www.debian.org/security/2010/dsa-2050http://www.kb.cert.org/vuls/id/196617http://www.mandriva.com/security/advisories?name=MDVSA-2010:087http://www.mandriva.com/security/advisories?name=MDVSA-2011:175http://www.redhat.com/support/errata/RHSA-2009-0480.htmlhttp://www.securityfocus.com/archive/1/502761/100/0/threadedhttp://www.securityfocus.com/bid/34568http://www.vupen.com/english/advisories/2009/1076http://www.vupen.com/english/advisories/2009/2928http://www.vupen.com/english/advisories/2010/0802http://www.vupen.com/english/advisories/2010/1040http://www.vupen.com/english/advisories/2010/1220https://bugs.launchpad.net/ubuntu/+source/poppler/+bug/361875https://bugzilla.redhat.com/show_bug.cgi?id=495907https://bugzilla.redhat.com/show_bug.cgi?id=526915https://exchange.xforce.ibmcloud.com/vulnerabilities/50185https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9957https://rhn.redhat.com/errata/RHSA-2009-1501.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1502.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1503.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1512.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=263028#c16http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035340.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035399.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035408.htmlhttp://poppler.freedesktop.org/releases.htmlhttp://secunia.com/advisories/34746http://secunia.com/advisories/35064http://secunia.com/advisories/35618http://secunia.com/advisories/37028http://secunia.com/advisories/37037http://secunia.com/advisories/37043http://secunia.com/advisories/37053http://secunia.com/advisories/37077http://secunia.com/advisories/37079http://secunia.com/advisories/39327http://secunia.com/advisories/39938http://wiki.rpath.com/Advisories:rPSA-2009-0059http://www.debian.org/security/2010/dsa-2028http://www.debian.org/security/2010/dsa-2050http://www.kb.cert.org/vuls/id/196617http://www.mandriva.com/security/advisories?name=MDVSA-2010:087http://www.mandriva.com/security/advisories?name=MDVSA-2011:175http://www.redhat.com/support/errata/RHSA-2009-0480.htmlhttp://www.securityfocus.com/archive/1/502761/100/0/threadedhttp://www.securityfocus.com/bid/34568http://www.vupen.com/english/advisories/2009/1076http://www.vupen.com/english/advisories/2009/2928http://www.vupen.com/english/advisories/2010/0802http://www.vupen.com/english/advisories/2010/1040http://www.vupen.com/english/advisories/2010/1220https://bugs.launchpad.net/ubuntu/+source/poppler/+bug/361875https://bugzilla.redhat.com/show_bug.cgi?id=495907https://bugzilla.redhat.com/show_bug.cgi?id=526915https://exchange.xforce.ibmcloud.com/vulnerabilities/50185https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9957https://rhn.redhat.com/errata/RHSA-2009-1501.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1502.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1503.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1512.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html
2009-04-23
Published