CVE-2009-3603

Severity
9.3CRITICAL
EPSS
6.3%
top 9.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21
Latest updateMay 3

Description

Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages5 packages

Debianxpdf< 3.02-2+3
Debianpoppler< 0.12.2-1+3
NVDpoppler/poppler0.12.0+51
NVDfoolabs/xpdf3.02pl1, 3.02pl2, 3.02pl3+2
NVDglyphandcog/xpdfreader3.00, 3.01, 3.02+2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2mhp-j72r-j69f: Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 32022-05-03
OSV
CVE-2009-3603: Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 32009-10-21
CVEList
CVE-2009-3603: Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 32009-10-21

📋Vendor Advisories

4
Ubuntu
poppler vulnerabilities2009-11-02
Ubuntu
poppler vulnerabilities2009-10-21
Red Hat
xpdf/poppler: SplashBitmap:: SplashBitmap integer overflow2009-10-14
Debian
CVE-2009-3603: poppler - Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3...2009

💬Community

2
Bugzilla
CVE-2009-0791 CVE-2009-360{3,4,6,7,8,9} Multiple poppler vulnerabilities2009-10-25
Bugzilla
CVE-2009-3603 xpdf/poppler: SplashBitmap::SplashBitmap integer overflow2009-10-02
CVE-2009-3603 (CRITICAL CVSS 9.3) | Integer overflow in the SplashBitma | cvebase.io