CVE-2009-3604
published 2009-10-21CVE-2009-3604: The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly…
PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
8.70%
94.5th percentile
The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that triggers a NULL pointer dereference or a heap-based buffer overflow.
Affected
75 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | poppler | < poppler 0.12.2-1 (bookworm) | poppler 0.12.2-1 (bookworm) |
| debian | xpdf | < poppler 0.12.2-1 (bookworm) | poppler 0.12.2-1 (bookworm) |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
poppler vulnerabilities
vendor_ubuntu·2009-11-02
CVE-2009-3603 poppler vulnerabilities
Title: poppler vulnerabilities
Summary: poppler vulnerabilities
USN-850-1 fixed vulnerabilities in poppler. This update provides the
corresponding updates for Ubuntu 9.10.
Original advisory details:
It was discovered that poppler contained multiple security issues when
parsing malformed PDF documents. If a user or automated system were tricked
into opening a crafted PDF file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Ubuntu
poppler vulnerabilities
vendor_ubuntu·2009-10-21
CVE-2009-0755 poppler vulnerabilities
Title: poppler vulnerabilities
Summary: poppler vulnerabilities
It was discovered that poppler contained multiple security issues when
parsing malformed PDF documents. If a user or automated system were tricked
into opening a crafted PDF file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
xpdf/poppler: Splash:: drawImage integer overflow and missing allocation return value check
vendor_redhat·2009-10-14·CVSS 9.3
CVE-2009-3604 [CRITICAL] CWE-190 xpdf/poppler: Splash:: drawImage integer overflow and missing allocation return value check
xpdf/poppler: Splash:: drawImage integer overflow and missing allocation return value check
The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that triggers a NULL pointer dereference or a heap-based buffer overflow.
Debian
CVE-2009-3604: poppler - The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, ...
vendor_debian·2009·CVSS 9.3
CVE-2009-3604 [CRITICAL] CVE-2009-3604: poppler - The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, ...
The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that triggers a NULL pointer dereference or a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 0.12.2-1)
bullseye: resolved (fixed in 0.12.2-1)
forky: resolved (fixed in 0.12.2-1)
sid: resolved (fixed in 0.12.2-1)
trixie: resolved (fixed in 0.12.2-1)
GHSA
GHSA-57v7-6q2r-896j: The Splash::drawImage function in Splash
ghsa_unreviewed·2022-05-03
CVE-2009-3604 [HIGH] GHSA-57v7-6q2r-896j: The Splash::drawImage function in Splash
The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that triggers a NULL pointer dereference or a heap-based buffer overflow.
OSV
CVE-2009-3604: The Splash::drawImage function in Splash
osv·2009-10-21·CVSS 9.3
CVE-2009-3604 [CRITICAL] CVE-2009-3604: The Splash::drawImage function in Splash
The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that triggers a NULL pointer dereference or a heap-based buffer overflow.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-0791 CVE-2009-360{3,4,6,7,8,9} Multiple poppler vulnerabilities
bugzilla·2009-10-25·CVSS 6.8
CVE-2009-0791 [MEDIUM] CVE-2009-0791 CVE-2009-360{3,4,6,7,8,9} Multiple poppler vulnerabilities
CVE-2009-0791 CVE-2009-360{3,4,6,7,8,9} Multiple poppler vulnerabilities
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #526637: CVE-2009-3608 xpdf/poppler: integer overflow in ObjectStream::ObjectStream (oCERT-2009-016)
bug #526911: CVE-2009-3604 xpdf/poppler: Splash::drawImage integer overflow and missing allocation return value check
bug #526915: CVE-2009-3603 xpdf/poppler: SplashBitmap::SplashBitmap integer overflow
bug #526924: CVE-2009-3607 poppler: create_surface_from_thumbnail_data integer overflow
bug #526877: CVE-2009-3606 xpdf/popple
Bugzilla
CVE-2009-3604 xpdf/poppler: Splash::drawImage integer overflow and missing allocation return value check
bugzilla·2009-10-02·CVSS 9.3
CVE-2009-3604 [CRITICAL] CVE-2009-3604 xpdf/poppler: Splash::drawImage integer overflow and missing allocation return value check
CVE-2009-3604 xpdf/poppler: Splash::drawImage integer overflow and missing allocation return value check
Adam Zabrocki reported flaws in xpdf's Splash::drawImage function related to buffer memory allocations:
2220 // allocate pixel buffers
2221 colorBuf = (SplashColorPtr)gmalloc((yp + 1) * w * nComps);
2222 if (srcAlpha) {
2223 alphaBuf = (Guchar *)gmalloc((yp + 1) * w);
2224 } else {
2225 alphaBuf = NULL;
2226 }
Values used to compute argument passed to gmalloc come from input PDF file. Properly chosen values will cause gmalloc to return NULL or buffer of insufficient size, leading to NULL pointer dereference or heap buffer overflow later.
Affected Splash output device is not available in xpdf 2.x versions and earlier. It is also not used in xpdf embedded in CUPS or tetex.
This was a
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl4.patchhttp://cgit.freedesktop.org/poppler/poppler/commit/?id=9cf2325fb2http://cgit.freedesktop.org/poppler/poppler/diff/?id=284a928996&id2=75c3466ba2http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035340.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035399.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035408.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlhttp://secunia.com/advisories/37023http://secunia.com/advisories/37028http://secunia.com/advisories/37037http://secunia.com/advisories/37042http://secunia.com/advisories/37043http://secunia.com/advisories/37053http://secunia.com/advisories/37077http://secunia.com/advisories/37079http://secunia.com/advisories/37114http://secunia.com/advisories/37159http://secunia.com/advisories/39327http://secunia.com/advisories/39938http://securitytracker.com/id?1023029http://site.pi3.com.pl/adv/xpdf.txthttp://sunsolve.sun.com/search/document.do?assetkey=1-66-274030-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021706.1-1http://www.debian.org/security/2010/dsa-2028http://www.debian.org/security/2010/dsa-2050http://www.mandriva.com/security/advisories?name=MDVSA-2009:287http://www.mandriva.com/security/advisories?name=MDVSA-2010:087http://www.mandriva.com/security/advisories?name=MDVSA-2011:175http://www.securityfocus.com/bid/36703http://www.ubuntu.com/usn/USN-850-1http://www.ubuntu.com/usn/USN-850-3http://www.vupen.com/english/advisories/2009/2924http://www.vupen.com/english/advisories/2009/2928http://www.vupen.com/english/advisories/2010/0802http://www.vupen.com/english/advisories/2010/1040http://www.vupen.com/english/advisories/2010/1220https://bugzilla.redhat.com/show_bug.cgi?id=526911https://exchange.xforce.ibmcloud.com/vulnerabilities/53795https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10969https://rhn.redhat.com/errata/RHSA-2009-1500.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1501.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1502.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1503.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1512.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00750.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00784.htmlftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl4.patchhttp://cgit.freedesktop.org/poppler/poppler/commit/?id=9cf2325fb2http://cgit.freedesktop.org/poppler/poppler/diff/?id=284a928996&id2=75c3466ba2http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035340.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035399.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035408.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlhttp://secunia.com/advisories/37023http://secunia.com/advisories/37028http://secunia.com/advisories/37037http://secunia.com/advisories/37042http://secunia.com/advisories/37043http://secunia.com/advisories/37053http://secunia.com/advisories/37077http://secunia.com/advisories/37079http://secunia.com/advisories/37114http://secunia.com/advisories/37159http://secunia.com/advisories/39327http://secunia.com/advisories/39938http://securitytracker.com/id?1023029http://site.pi3.com.pl/adv/xpdf.txthttp://sunsolve.sun.com/search/document.do?assetkey=1-66-274030-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021706.1-1http://www.debian.org/security/2010/dsa-2028http://www.debian.org/security/2010/dsa-2050http://www.mandriva.com/security/advisories?name=MDVSA-2009:287http://www.mandriva.com/security/advisories?name=MDVSA-2010:087http://www.mandriva.com/security/advisories?name=MDVSA-2011:175http://www.securityfocus.com/bid/36703http://www.ubuntu.com/usn/USN-850-1http://www.ubuntu.com/usn/USN-850-3http://www.vupen.com/english/advisories/2009/2924http://www.vupen.com/english/advisories/2009/2928http://www.vupen.com/english/advisories/2010/0802http://www.vupen.com/english/advisories/2010/1040http://www.vupen.com/english/advisories/2010/1220https://bugzilla.redhat.com/show_bug.cgi?id=526911https://exchange.xforce.ibmcloud.com/vulnerabilities/53795https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10969https://rhn.redhat.com/errata/RHSA-2009-1500.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1501.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1502.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1503.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1512.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00750.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00784.html
2009-10-21
Published