CVE-2009-3606
published 2009-10-21CVE-2009-3606: Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers…
PriorityP347critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
8.63%
94.5th percentile
Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
Affected
68 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | poppler | < poppler 0.12.2-1 (bookworm) | poppler 0.12.2-1 (bookworm) |
| debian | xpdf | < poppler 0.12.2-1 (bookworm) | poppler 0.12.2-1 (bookworm) |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
KOffice vulnerabilities
vendor_ubuntu·2010-08-17·CVSS 4.3
CVE-2009-0165 [MEDIUM] KOffice vulnerabilities
Title: KOffice vulnerabilities
Summary: PDF import support has been disabled in KWord due to many security
vulnerabilities that could be used by an attacker to run programs as your
login.
Will Dormann, Alin Rad Pop, Braden Thomas, and Drew Yao discovered that the
Xpdf used in KOffice contained multiple security issues in its JBIG2
decoder. If a user or automated system were tricked into opening a crafted
PDF file, an attacker could cause a denial of service or execute arbitrary
code with privileges of the user invoking the program. (CVE-2009-0146,
CVE-2009-0147, CVE-2009-0166, CVE-2009-0799, CVE-2009-0800, CVE-2009-1179,
CVE-2009-1180, CVE-2009-1181)
It was discovered that the Xpdf used in KOffice contained multiple security
issues when parsing malformed PDF documents. If a user or auto
Red Hat
xpdf/poppler: PSOutputDev:: doImageL1Sep integer overflow
vendor_redhat·2009-10-14·CVSS 9.3
CVE-2009-3606 [CRITICAL] CWE-190 xpdf/poppler: PSOutputDev:: doImageL1Sep integer overflow
xpdf/poppler: PSOutputDev:: doImageL1Sep integer overflow
Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
Debian
CVE-2009-3606: poppler - Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl...
vendor_debian·2009·CVSS 9.3
CVE-2009-3606 [CRITICAL] CVE-2009-3606: poppler - Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl...
Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 0.12.2-1)
bullseye: resolved (fixed in 0.12.2-1)
forky: resolved (fixed in 0.12.2-1)
sid: resolved (fixed in 0.12.2-1)
trixie: resolved (fixed in 0.12.2-1)
GHSA
GHSA-75g3-x63m-xg86: Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3
ghsa_unreviewed·2022-05-03
CVE-2009-3606 [HIGH] GHSA-75g3-x63m-xg86: Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3
Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
OSV
CVE-2009-3606: Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3
osv·2009-10-21·CVSS 9.3
CVE-2009-3606 [CRITICAL] CVE-2009-3606: Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3
Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
No detection rules found.
No public exploits indexed.
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl4.patchhttp://cgit.freedesktop.org/poppler/poppler/diff/poppler/PSOutputDev.cc?id=7b2d314a61http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035340.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035399.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035408.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlhttp://secunia.com/advisories/37023http://secunia.com/advisories/37037http://secunia.com/advisories/37042http://secunia.com/advisories/37043http://secunia.com/advisories/37053http://secunia.com/advisories/37077http://secunia.com/advisories/37159http://secunia.com/advisories/39327http://secunia.com/advisories/39938http://securitytracker.com/id?1023029http://sunsolve.sun.com/search/document.do?assetkey=1-66-274030-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021706.1-1http://www.debian.org/security/2009/dsa-1941http://www.debian.org/security/2010/dsa-2028http://www.debian.org/security/2010/dsa-2050http://www.mandriva.com/security/advisories?name=MDVSA-2009:287http://www.mandriva.com/security/advisories?name=MDVSA-2010:087http://www.mandriva.com/security/advisories?name=MDVSA-2011:175http://www.openwall.com/lists/oss-security/2009/12/01/1http://www.openwall.com/lists/oss-security/2009/12/01/5http://www.openwall.com/lists/oss-security/2009/12/01/6http://www.securityfocus.com/bid/36703http://www.vupen.com/english/advisories/2009/2924http://www.vupen.com/english/advisories/2009/2928http://www.vupen.com/english/advisories/2010/0802http://www.vupen.com/english/advisories/2010/1040http://www.vupen.com/english/advisories/2010/1220https://bugzilla.redhat.com/show_bug.cgi?id=526877https://exchange.xforce.ibmcloud.com/vulnerabilities/53798https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11289https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7836https://rhn.redhat.com/errata/RHSA-2009-1500.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1501.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1502.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00750.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00784.htmlftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl4.patchhttp://cgit.freedesktop.org/poppler/poppler/diff/poppler/PSOutputDev.cc?id=7b2d314a61http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035340.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035399.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035408.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlhttp://secunia.com/advisories/37023http://secunia.com/advisories/37037http://secunia.com/advisories/37042http://secunia.com/advisories/37043http://secunia.com/advisories/37053http://secunia.com/advisories/37077http://secunia.com/advisories/37159http://secunia.com/advisories/39327http://secunia.com/advisories/39938http://securitytracker.com/id?1023029http://sunsolve.sun.com/search/document.do?assetkey=1-66-274030-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021706.1-1http://www.debian.org/security/2009/dsa-1941http://www.debian.org/security/2010/dsa-2028http://www.debian.org/security/2010/dsa-2050http://www.mandriva.com/security/advisories?name=MDVSA-2009:287http://www.mandriva.com/security/advisories?name=MDVSA-2010:087http://www.mandriva.com/security/advisories?name=MDVSA-2011:175http://www.openwall.com/lists/oss-security/2009/12/01/1http://www.openwall.com/lists/oss-security/2009/12/01/5http://www.openwall.com/lists/oss-security/2009/12/01/6http://www.securityfocus.com/bid/36703http://www.vupen.com/english/advisories/2009/2924http://www.vupen.com/english/advisories/2009/2928http://www.vupen.com/english/advisories/2010/0802http://www.vupen.com/english/advisories/2010/1040http://www.vupen.com/english/advisories/2010/1220https://bugzilla.redhat.com/show_bug.cgi?id=526877https://exchange.xforce.ibmcloud.com/vulnerabilities/53798https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11289https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7836https://rhn.redhat.com/errata/RHSA-2009-1500.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1501.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1502.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00750.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00784.html
2009-10-21
Published