CVE-2009-3609
Severity
4.3MEDIUM
EPSS
6.0%
top 9.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 21
Latest updateMay 3
Description
Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read.
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9
Affected Packages5 packages
Patches
🔴Vulnerability Details
3GHSA
▶
CVEList
▶
📋Vendor Advisories
5Debian▶
CVE-2009-3609: poppler - Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf b...↗2009