CVE-2009-3603
published 2009-10-21CVE-2009-3603: Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute…
PriorityP343critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
8.58%
94.5th percentile
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.
Affected
68 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | poppler | < poppler 0.12.2-1 (bookworm) | poppler 0.12.2-1 (bookworm) |
| debian | xpdf | < poppler 0.12.2-1 (bookworm) | poppler 0.12.2-1 (bookworm) |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| poppler | poppler | <= 0.12.0 | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
poppler vulnerabilities
vendor_ubuntu·2009-11-02
CVE-2009-3603 poppler vulnerabilities
Title: poppler vulnerabilities
Summary: poppler vulnerabilities
USN-850-1 fixed vulnerabilities in poppler. This update provides the
corresponding updates for Ubuntu 9.10.
Original advisory details:
It was discovered that poppler contained multiple security issues when
parsing malformed PDF documents. If a user or automated system were tricked
into opening a crafted PDF file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Ubuntu
poppler vulnerabilities
vendor_ubuntu·2009-10-21
CVE-2009-0755 poppler vulnerabilities
Title: poppler vulnerabilities
Summary: poppler vulnerabilities
It was discovered that poppler contained multiple security issues when
parsing malformed PDF documents. If a user or automated system were tricked
into opening a crafted PDF file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
xpdf/poppler: SplashBitmap:: SplashBitmap integer overflow
vendor_redhat·2009-10-14·CVSS 5.0
CVE-2009-3603 [MEDIUM] CWE-190 xpdf/poppler: SplashBitmap:: SplashBitmap integer overflow
xpdf/poppler: SplashBitmap:: SplashBitmap integer overflow
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.
Debian
CVE-2009-3603: poppler - Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3...
vendor_debian·2009·CVSS 5.0
CVE-2009-3603 [MEDIUM] CVE-2009-3603: poppler - Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3...
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.
Scope: local
bookworm: resolved (fixed in 0.12.2-1)
bullseye: resolved (fixed in 0.12.2-1)
forky: resolved (fixed in 0.12.2-1)
sid: resolved (fixed in 0.12.2-1)
trixie: resolved (fixed in 0.12.2-1)
GHSA
GHSA-2mhp-j72r-j69f: Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3
ghsa_unreviewed·2022-05-03·CVSS 5.0
CVE-2009-3603 [MEDIUM] GHSA-2mhp-j72r-j69f: Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.
OSV
CVE-2009-3603: Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3
osv·2009-10-21·CVSS 5.0
CVE-2009-3603 [MEDIUM] CVE-2009-3603: Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-0791 CVE-2009-360{3,4,6,7,8,9} Multiple poppler vulnerabilities
bugzilla·2009-10-25·CVSS 6.8
CVE-2009-0791 [MEDIUM] CVE-2009-0791 CVE-2009-360{3,4,6,7,8,9} Multiple poppler vulnerabilities
CVE-2009-0791 CVE-2009-360{3,4,6,7,8,9} Multiple poppler vulnerabilities
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #526637: CVE-2009-3608 xpdf/poppler: integer overflow in ObjectStream::ObjectStream (oCERT-2009-016)
bug #526911: CVE-2009-3604 xpdf/poppler: Splash::drawImage integer overflow and missing allocation return value check
bug #526915: CVE-2009-3603 xpdf/poppler: SplashBitmap::SplashBitmap integer overflow
bug #526924: CVE-2009-3607 poppler: create_surface_from_thumbnail_data integer overflow
bug #526877: CVE-2009-3606 xpdf/popple
Bugzilla
CVE-2009-3603 xpdf/poppler: SplashBitmap::SplashBitmap integer overflow
bugzilla·2009-10-02·CVSS 5.0
CVE-2009-3603 [MEDIUM] CVE-2009-3603 xpdf/poppler: SplashBitmap::SplashBitmap integer overflow
CVE-2009-3603 xpdf/poppler: SplashBitmap::SplashBitmap integer overflow
Integer overflow was discovered in SplashBitmap::SplashBitmap when computing memory allocation requirements. This issue was previously reported as CVE-2009-1188 / bug #495907 and addressed in poppler via gmalloc -> gmallocn change via:
http://cgit.freedesktop.org/poppler/poppler/commit/?id=9cf2325fb2
However, such fix is not sufficient, as overflow can occur even during rowSize calculation.
Splash output device is not present in xpdf 2.x, it's also not in the xpdf code embedded in CUPS or tetex.
Discussion:
Created attachment 363486
xpdf upstream patch from Derek B. Noonburg
---
xpdf is fixed now for the CVE-2009-1188/CVE-2009-3603 in xpdf-3.02pl4:
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl4.patch
https://bugzil
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl4.patchhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035340.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035399.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035408.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlhttp://poppler.freedesktop.org/http://secunia.com/advisories/37034http://secunia.com/advisories/37053http://secunia.com/advisories/37054http://secunia.com/advisories/37114http://secunia.com/advisories/37159http://secunia.com/advisories/39327http://secunia.com/advisories/39938http://securitytracker.com/id?1023029http://sunsolve.sun.com/search/document.do?assetkey=1-66-274030-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021706.1-1http://www.debian.org/security/2010/dsa-2028http://www.debian.org/security/2010/dsa-2050http://www.mandriva.com/security/advisories?name=MDVSA-2009:287http://www.mandriva.com/security/advisories?name=MDVSA-2010:087http://www.mandriva.com/security/advisories?name=MDVSA-2011:175http://www.securityfocus.com/bid/36703http://www.ubuntu.com/usn/USN-850-1http://www.ubuntu.com/usn/USN-850-3http://www.vupen.com/english/advisories/2009/2924http://www.vupen.com/english/advisories/2009/2925http://www.vupen.com/english/advisories/2010/0802http://www.vupen.com/english/advisories/2010/1040http://www.vupen.com/english/advisories/2010/1220https://bugzilla.redhat.com/show_bug.cgi?id=526915https://exchange.xforce.ibmcloud.com/vulnerabilities/53793https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9671https://rhn.redhat.com/errata/RHSA-2009-1504.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00750.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00784.htmlftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl4.patchhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035340.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035399.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035408.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlhttp://poppler.freedesktop.org/http://secunia.com/advisories/37034http://secunia.com/advisories/37053http://secunia.com/advisories/37054http://secunia.com/advisories/37114http://secunia.com/advisories/37159http://secunia.com/advisories/39327http://secunia.com/advisories/39938http://securitytracker.com/id?1023029http://sunsolve.sun.com/search/document.do?assetkey=1-66-274030-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021706.1-1http://www.debian.org/security/2010/dsa-2028http://www.debian.org/security/2010/dsa-2050http://www.mandriva.com/security/advisories?name=MDVSA-2009:287http://www.mandriva.com/security/advisories?name=MDVSA-2010:087http://www.mandriva.com/security/advisories?name=MDVSA-2011:175http://www.securityfocus.com/bid/36703http://www.ubuntu.com/usn/USN-850-1http://www.ubuntu.com/usn/USN-850-3http://www.vupen.com/english/advisories/2009/2924http://www.vupen.com/english/advisories/2009/2925http://www.vupen.com/english/advisories/2010/0802http://www.vupen.com/english/advisories/2010/1040http://www.vupen.com/english/advisories/2010/1220https://bugzilla.redhat.com/show_bug.cgi?id=526915https://exchange.xforce.ibmcloud.com/vulnerabilities/53793https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9671https://rhn.redhat.com/errata/RHSA-2009-1504.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00750.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00784.html
2009-10-21
Published