CVE-2009-3609
published 2009-10-21CVE-2009-3609: Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
4.48%
90.4th percentile
Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read.
Affected
68 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | poppler | < poppler 0.12.2-1 (bookworm) | poppler 0.12.2-1 (bookworm) |
| debian | xpdf | < poppler 0.12.2-1 (bookworm) | poppler 0.12.2-1 (bookworm) |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| freedesktop | poppler | >= 0 < 0.12.2-1 | 0.12.2-1 |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| poppler | poppler | <= 0.12.0 | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
| poppler | poppler | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hr5j-672h-fcgc: Integer overflow in the ImageStream::ImageStream function in Stream
ghsa_unreviewed·2022-05-03
CVE-2009-3609 [MEDIUM] GHSA-hr5j-672h-fcgc: Integer overflow in the ImageStream::ImageStream function in Stream
Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read.
OSV
CVE-2009-3609: Integer overflow in the ImageStream::ImageStream function in Stream
osv·2009-10-21·CVSS 4.3
CVE-2009-3609 [MEDIUM] CVE-2009-3609: Integer overflow in the ImageStream::ImageStream function in Stream
Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read.
Ubuntu
KOffice vulnerabilities
vendor_ubuntu·2010-08-17·CVSS 4.3
CVE-2009-0165 [MEDIUM] KOffice vulnerabilities
Title: KOffice vulnerabilities
Summary: PDF import support has been disabled in KWord due to many security
vulnerabilities that could be used by an attacker to run programs as your
login.
Will Dormann, Alin Rad Pop, Braden Thomas, and Drew Yao discovered that the
Xpdf used in KOffice contained multiple security issues in its JBIG2
decoder. If a user or automated system were tricked into opening a crafted
PDF file, an attacker could cause a denial of service or execute arbitrary
code with privileges of the user invoking the program. (CVE-2009-0146,
CVE-2009-0147, CVE-2009-0166, CVE-2009-0799, CVE-2009-0800, CVE-2009-1179,
CVE-2009-1180, CVE-2009-1181)
It was discovered that the Xpdf used in KOffice contained multiple security
issues when parsing malformed PDF documents. If a user or auto
Ubuntu
poppler vulnerabilities
vendor_ubuntu·2009-11-02
CVE-2009-3603 poppler vulnerabilities
Title: poppler vulnerabilities
Summary: poppler vulnerabilities
USN-850-1 fixed vulnerabilities in poppler. This update provides the
corresponding updates for Ubuntu 9.10.
Original advisory details:
It was discovered that poppler contained multiple security issues when
parsing malformed PDF documents. If a user or automated system were tricked
into opening a crafted PDF file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Ubuntu
poppler vulnerabilities
vendor_ubuntu·2009-10-21
CVE-2009-0755 poppler vulnerabilities
Title: poppler vulnerabilities
Summary: poppler vulnerabilities
It was discovered that poppler contained multiple security issues when
parsing malformed PDF documents. If a user or automated system were tricked
into opening a crafted PDF file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
xpdf/poppler: ImageStream:: ImageStream integer overflow
vendor_redhat·2009-10-14·CVSS 4.3
CVE-2009-3609 [MEDIUM] CWE-190 xpdf/poppler: ImageStream:: ImageStream integer overflow
xpdf/poppler: ImageStream:: ImageStream integer overflow
Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read.
Debian
CVE-2009-3609: poppler - Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf b...
vendor_debian·2009·CVSS 4.3
CVE-2009-3609 [MEDIUM] CVE-2009-3609: poppler - Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf b...
Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read.
Scope: local
bookworm: resolved (fixed in 0.12.2-1)
bullseye: resolved (fixed in 0.12.2-1)
forky: resolved (fixed in 0.12.2-1)
sid: resolved (fixed in 0.12.2-1)
trixie: resolved (fixed in 0.12.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-0791 CVE-2009-360{3,4,6,7,8,9} Multiple poppler vulnerabilities
bugzilla·2009-10-25·CVSS 6.8
CVE-2009-0791 [MEDIUM] CVE-2009-0791 CVE-2009-360{3,4,6,7,8,9} Multiple poppler vulnerabilities
CVE-2009-0791 CVE-2009-360{3,4,6,7,8,9} Multiple poppler vulnerabilities
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #526637: CVE-2009-3608 xpdf/poppler: integer overflow in ObjectStream::ObjectStream (oCERT-2009-016)
bug #526911: CVE-2009-3604 xpdf/poppler: Splash::drawImage integer overflow and missing allocation return value check
bug #526915: CVE-2009-3603 xpdf/poppler: SplashBitmap::SplashBitmap integer overflow
bug #526924: CVE-2009-3607 poppler: create_surface_from_thumbnail_data integer overflow
bug #526877: CVE-2009-3606 xpdf/popple
Bugzilla
CVE-2009-3609 xpdf/poppler: ImageStream::ImageStream integer overflow
bugzilla·2009-10-02·CVSS 4.3
CVE-2009-3609 [MEDIUM] CVE-2009-3609 xpdf/poppler: ImageStream::ImageStream integer overflow
CVE-2009-3609 xpdf/poppler: ImageStream::ImageStream integer overflow
An integer overflow flaw exists in xpdf's ImageStream::ImageStream (Stream.cc) when calculating size of the imgLine buffer:
320 nVals = width * nComps;
321 if (nBits == 1) {
322 imgLineSize = (nVals + 7) & ~7;
323 } else {
324 imgLineSize = nVals;
325 }
326 imgLine = (Guchar *)gmallocn(imgLineSize, sizeof(Guchar));
width and nComps used go compute nVals value come from the input PDF file. Their multiplication may overflow / wrap, resulting in smaller imgLine buffer allocation than expected.
ImageStream always uses nVals as an upper bound when writing data into imgLine. Therefore, no buffer overflow occurs in ImageStream, but NULL pointer dereference may occur (gmallocn returns NULL when called with imgLineSize 0).
P
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl4.patchhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035340.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035399.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035408.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlhttp://poppler.freedesktop.org/http://secunia.com/advisories/37023http://secunia.com/advisories/37028http://secunia.com/advisories/37034http://secunia.com/advisories/37037http://secunia.com/advisories/37043http://secunia.com/advisories/37051http://secunia.com/advisories/37054http://secunia.com/advisories/37061http://secunia.com/advisories/37077http://secunia.com/advisories/37079http://secunia.com/advisories/37114http://secunia.com/advisories/37159http://secunia.com/advisories/39327http://secunia.com/advisories/39938http://securitytracker.com/id?1023029http://sunsolve.sun.com/search/document.do?assetkey=1-66-274030-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021706.1-1http://www.debian.org/security/2010/dsa-2028http://www.debian.org/security/2010/dsa-2050http://www.mandriva.com/security/advisories?name=MDVSA-2009:287http://www.mandriva.com/security/advisories?name=MDVSA-2009:334http://www.mandriva.com/security/advisories?name=MDVSA-2011:175http://www.redhat.com/support/errata/RHSA-2010-0755.htmlhttp://www.securityfocus.com/bid/36703http://www.ubuntu.com/usn/USN-850-1http://www.ubuntu.com/usn/USN-850-3http://www.vupen.com/english/advisories/2009/2924http://www.vupen.com/english/advisories/2009/2925http://www.vupen.com/english/advisories/2009/2926http://www.vupen.com/english/advisories/2009/2928http://www.vupen.com/english/advisories/2010/0802http://www.vupen.com/english/advisories/2010/1220https://bugzilla.redhat.com/show_bug.cgi?id=526893https://exchange.xforce.ibmcloud.com/vulnerabilities/53800https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11043https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8134https://rhn.redhat.com/errata/RHSA-2009-1500.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1501.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1502.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1503.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1504.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1512.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1513.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00750.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-October/msg00784.htmlftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl4.patchhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035340.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035399.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035408.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlhttp://poppler.freedesktop.org/http://secunia.com/advisories/37023http://secunia.com/advisories/37028http://secunia.com/advisories/37034http://secunia.com/advisories/37037http://secunia.com/advisories/37043http://secunia.com/advisories/37051http://secunia.com/advisories/37054http://secunia.com/advisories/37061http://secunia.com/advisories/37077http://secunia.com/advisories/37079http://secunia.com/advisories/37114http://secunia.com/advisories/37159http://secunia.com/advisories/39327http://secunia.com/advisories/39938http://securitytracker.com/id?1023029http://sunsolve.sun.com/search/document.do?assetkey=1-66-274030-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021706.1-1http://www.debian.org/security/2010/dsa-2028http://www.debian.org/security/2010/dsa-2050http://www.mandriva.com/security/advisories?name=MDVSA-2009:287http://www.mandriva.com/security/advisories?name=MDVSA-2009:334http://www.mandriva.com/security/advisories?name=MDVSA-2011:175http://www.redhat.com/support/errata/RHSA-2010-0755.htmlhttp://www.securityfocus.com/bid/36703http://www.ubuntu.com/usn/USN-850-1http://www.ubuntu.com/usn/USN-850-3http://www.vupen.com/english/advisories/2009/2924http://www.vupen.com/english/advisories/2009/2925http://www.vupen.com/english/advisories/2009/2926http://www.vupen.com/english/advisories/2009/2928http://www.vupen.com/english/advisories/2010/0802http://www.vupen.com/english/advisories/2010/1220https://bugzilla.redhat.com/show_bug.cgi?id=526893https://exchange.xforce.ibmcloud.com/vulnerabilities/53800https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11043https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8134https://rhn.redhat.com/errata/RHSA-2009-1500.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1501.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1502.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1503.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1504.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1512.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1513.html
+ 2 more references
2009-10-21
Published