CVE-2009-4035
published 2009-12-21CVE-2009-4035: The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not…
PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.79%
88.8th percentile
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | poppler | < poppler 0.5.1-1 (bookworm) | poppler 0.5.1-1 (bookworm) |
| debian | xpdf | < poppler 0.5.1-1 (bookworm) | poppler 0.5.1-1 (bookworm) |
| freedesktop | poppler | >= 0 < 0.5.1-1 | 0.5.1-1 |
| freedesktop | poppler | >= 0 < 0.5.1-1 | 0.5.1-1 |
| freedesktop | poppler | >= 0 < 0.5.1-1 | 0.5.1-1 |
| freedesktop | poppler | >= 0 < 0.5.1-1 | 0.5.1-1 |
| gnome | gpdf | — | — |
| kde | kdegraphics | — | — |
| kde | kpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | >= 0 < 3.01-1 | 3.01-1 |
| xpdf | xpdf | >= 0 < 3.01-1 | 3.01-1 |
| xpdf | xpdf | >= 0 < 3.01-1 | 3.01-1 |
| xpdf | xpdf | >= 0 < 3.01-1 | 3.01-1 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9rm4-mjvc-4m49: The FoFiType1::parse function in fofi/FoFiType1
ghsa_unreviewed·2022-05-02
CVE-2009-4035 [HIGH] CWE-94 GHSA-9rm4-mjvc-4m49: The FoFiType1::parse function in fofi/FoFiType1
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.
OSV
CVE-2009-4035: The FoFiType1::parse function in fofi/FoFiType1
osv·2009-12-21·CVSS 9.3
CVE-2009-4035 [CRITICAL] CVE-2009-4035: The FoFiType1::parse function in fofi/FoFiType1
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.
Red Hat
xpdf: buffer overflow in FoFiType1::parse
vendor_redhat·2009-12-16·CVSS 9.3
CVE-2009-4035 [CRITICAL] xpdf: buffer overflow in FoFiType1::parse
xpdf: buffer overflow in FoFiType1::parse
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.
Debian
CVE-2009-4035: poppler - The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kp...
vendor_debian·2009·CVSS 9.3
CVE-2009-4035 [CRITICAL] CVE-2009-4035: poppler - The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kp...
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.
Scope: local
bookworm: resolved (fixed in 0.5.1-1)
bullseye: resolved (fixed in 0.5.1-1)
forky: resolved (fixed in 0.5.1-1)
sid: resolved (fixed in 0.5.1-1)
trixie: resolved (fixed in 0.5.1-1)
No detection rules found.
No public exploits indexed.
http://cgit.freedesktop.org/poppler/poppler/diff/fofi/FoFiType1.cc?id=4b4fc5c0http://cgit.freedesktop.org/poppler/poppler/tree/fofi/FoFiType1.cc?id=4b4fc5c017bf147c9069bbce32fc14467bd2a81ahttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.htmlhttp://secunia.com/advisories/37641http://secunia.com/advisories/37781http://secunia.com/advisories/37787http://secunia.com/advisories/37793http://www.redhat.com/support/errata/RHSA-2009-1680.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1681.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1682.htmlhttp://www.securityfocus.com/bid/37350http://www.securitytracker.com/id?1023356http://www.vupen.com/english/advisories/2009/3555https://bugzilla.redhat.com/show_bug.cgi?id=541614https://exchange.xforce.ibmcloud.com/vulnerabilities/54831https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10996http://cgit.freedesktop.org/poppler/poppler/diff/fofi/FoFiType1.cc?id=4b4fc5c0http://cgit.freedesktop.org/poppler/poppler/tree/fofi/FoFiType1.cc?id=4b4fc5c017bf147c9069bbce32fc14467bd2a81ahttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.htmlhttp://secunia.com/advisories/37641http://secunia.com/advisories/37781http://secunia.com/advisories/37787http://secunia.com/advisories/37793http://www.redhat.com/support/errata/RHSA-2009-1680.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1681.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1682.htmlhttp://www.securityfocus.com/bid/37350http://www.securitytracker.com/id?1023356http://www.vupen.com/english/advisories/2009/3555https://bugzilla.redhat.com/show_bug.cgi?id=541614https://exchange.xforce.ibmcloud.com/vulnerabilities/54831https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10996
2009-12-21
Published