CVE-2009-3608
published 2009-10-21CVE-2009-3608: Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF…
PriorityP348critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
10.23%
95.2th percentile
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
Affected
68 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | poppler | < poppler 0.12.2-1 (bookworm) | poppler 0.12.2-1 (bookworm) |
| debian | xpdf | < poppler 0.12.2-1 (bookworm) | poppler 0.12.2-1 (bookworm) |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| poppler | poppler | <= 0.12.0 | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6fmp-2mpq-35v4: Integer overflow in the ObjectStream::ObjectStream function in XRef
ghsa_unreviewed·2022-05-03
CVE-2009-3608 [HIGH] GHSA-6fmp-2mpq-35v4: Integer overflow in the ObjectStream::ObjectStream function in XRef
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
OSV
CVE-2009-3608: Integer overflow in the ObjectStream::ObjectStream function in XRef
osv·2009-10-21·CVSS 9.3
CVE-2009-3608 [CRITICAL] CVE-2009-3608: Integer overflow in the ObjectStream::ObjectStream function in XRef
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
Ubuntu
KOffice vulnerabilities
vendor_ubuntu·2010-08-17·CVSS 4.3
CVE-2009-0165 [MEDIUM] KOffice vulnerabilities
Title: KOffice vulnerabilities
Summary: PDF import support has been disabled in KWord due to many security
vulnerabilities that could be used by an attacker to run programs as your
login.
Will Dormann, Alin Rad Pop, Braden Thomas, and Drew Yao discovered that the
Xpdf used in KOffice contained multiple security issues in its JBIG2
decoder. If a user or automated system were tricked into opening a crafted
PDF file, an attacker could cause a denial of service or execute arbitrary
code with privileges of the user invoking the program. (CVE-2009-0146,
CVE-2009-0147, CVE-2009-0166, CVE-2009-0799, CVE-2009-0800, CVE-2009-1179,
CVE-2009-1180, CVE-2009-1181)
It was discovered that the Xpdf used in KOffice contained multiple security
issues when parsing malformed PDF documents. If a user or auto
Ubuntu
poppler vulnerabilities
vendor_ubuntu·2009-11-02
CVE-2009-3603 poppler vulnerabilities
Title: poppler vulnerabilities
Summary: poppler vulnerabilities
USN-850-1 fixed vulnerabilities in poppler. This update provides the
corresponding updates for Ubuntu 9.10.
Original advisory details:
It was discovered that poppler contained multiple security issues when
parsing malformed PDF documents. If a user or automated system were tricked
into opening a crafted PDF file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Ubuntu
poppler vulnerabilities
vendor_ubuntu·2009-10-21
CVE-2009-0755 poppler vulnerabilities
Title: poppler vulnerabilities
Summary: poppler vulnerabilities
It was discovered that poppler contained multiple security issues when
parsing malformed PDF documents. If a user or automated system were tricked
into opening a crafted PDF file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
xpdf/poppler: integer overflow in ObjectStream::ObjectStream (oCERT-2009-016)
vendor_redhat·2009-10-14·CVSS 9.3
CVE-2009-3608 [CRITICAL] CWE-190 xpdf/poppler: integer overflow in ObjectStream::ObjectStream (oCERT-2009-016)
xpdf/poppler: integer overflow in ObjectStream::ObjectStream (oCERT-2009-016)
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
Debian
CVE-2009-3608: poppler - Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3...
vendor_debian·2009·CVSS 9.3
CVE-2009-3608 [CRITICAL] CVE-2009-3608: poppler - Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3...
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 0.12.2-1)
bullseye: resolved (fixed in 0.12.2-1)
forky: resolved (fixed in 0.12.2-1)
sid: resolved (fixed in 0.12.2-1)
trixie: resolved (fixed in 0.12.2-1)
No detection rules found.
No public exploits indexed.
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl4.patchhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035340.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035399.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035408.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlhttp://poppler.freedesktop.org/http://secunia.com/advisories/37028http://secunia.com/advisories/37034http://secunia.com/advisories/37037http://secunia.com/advisories/37043http://secunia.com/advisories/37051http://secunia.com/advisories/37053http://secunia.com/advisories/37054http://secunia.com/advisories/37061http://secunia.com/advisories/37077http://secunia.com/advisories/37079http://secunia.com/advisories/37114http://secunia.com/advisories/37159http://secunia.com/advisories/39327http://secunia.com/advisories/39938http://securitytracker.com/id?1023029http://sunsolve.sun.com/search/document.do?assetkey=1-66-274030-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021706.1-1http://www.debian.org/security/2009/dsa-1941http://www.debian.org/security/2010/dsa-2028http://www.debian.org/security/2010/dsa-2050http://www.mandriva.com/security/advisories?name=MDVSA-2009:287http://www.mandriva.com/security/advisories?name=MDVSA-2009:334http://www.mandriva.com/security/advisories?name=MDVSA-2011:175http://www.ocert.org/advisories/ocert-2009-016.htmlhttp://www.openwall.com/lists/oss-security/2009/12/01/1http://www.openwall.com/lists/oss-security/2009/12/01/5http://www.openwall.com/lists/oss-security/2009/12/01/6http://www.securityfocus.com/bid/36703http://www.ubuntu.com/usn/USN-850-1http://www.ubuntu.com/usn/USN-850-3http://www.vupen.com/english/advisories/2009/2924http://www.vupen.com/english/advisories/2009/2925http://www.vupen.com/english/advisories/2009/2926http://www.vupen.com/english/advisories/2009/2928http://www.vupen.com/english/advisories/2010/0802http://www.vupen.com/english/advisories/2010/1220https://bugzilla.redhat.com/show_bug.cgi?id=526637https://exchange.xforce.ibmcloud.com/vulnerabilities/53794https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9536https://rhn.redhat.com/errata/RHSA-2009-1501.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1502.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1503.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1504.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1512.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1513.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00750.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00784.htmlftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl4.patchhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035340.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035399.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035408.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlhttp://poppler.freedesktop.org/http://secunia.com/advisories/37028http://secunia.com/advisories/37034http://secunia.com/advisories/37037http://secunia.com/advisories/37043http://secunia.com/advisories/37051http://secunia.com/advisories/37053http://secunia.com/advisories/37054http://secunia.com/advisories/37061http://secunia.com/advisories/37077http://secunia.com/advisories/37079http://secunia.com/advisories/37114http://secunia.com/advisories/37159http://secunia.com/advisories/39327http://secunia.com/advisories/39938http://securitytracker.com/id?1023029http://sunsolve.sun.com/search/document.do?assetkey=1-66-274030-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021706.1-1http://www.debian.org/security/2009/dsa-1941http://www.debian.org/security/2010/dsa-2028http://www.debian.org/security/2010/dsa-2050http://www.mandriva.com/security/advisories?name=MDVSA-2009:287http://www.mandriva.com/security/advisories?name=MDVSA-2009:334http://www.mandriva.com/security/advisories?name=MDVSA-2011:175http://www.ocert.org/advisories/ocert-2009-016.htmlhttp://www.openwall.com/lists/oss-security/2009/12/01/1http://www.openwall.com/lists/oss-security/2009/12/01/5http://www.openwall.com/lists/oss-security/2009/12/01/6http://www.securityfocus.com/bid/36703http://www.ubuntu.com/usn/USN-850-1http://www.ubuntu.com/usn/USN-850-3http://www.vupen.com/english/advisories/2009/2924http://www.vupen.com/english/advisories/2009/2925http://www.vupen.com/english/advisories/2009/2926http://www.vupen.com/english/advisories/2009/2928http://www.vupen.com/english/advisories/2010/0802http://www.vupen.com/english/advisories/2010/1220https://bugzilla.redhat.com/show_bug.cgi?id=526637https://exchange.xforce.ibmcloud.com/vulnerabilities/53794https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9536https://rhn.redhat.com/errata/RHSA-2009-1501.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1502.html
+ 6 more references
2009-10-21
Published