CVE-2009-0791
Published Jun 9, 2009
Last updated 2 years ago
Overview
- Description
- Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1) Decrypt.cxx, (2) FoFiTrueType.cxx, (3) gmem.c, (4) JBIG2Stream.cxx, and (5) PSOutputDev.cxx in pdftops/. NOTE: the JBIG2Stream.cxx vector may overlap CVE-2009-1179.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-189
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:apple:cups:1.1.17:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8335D4E3-563D-4288-B708-A9635BCA595F" }, { "criteria": "cpe:2.3:a:apple:cups:1.1.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "96592A93-4967-4B91-BCF7-558DC472E7BC" }, { "criteria": "cpe:2.3:a:apple:cups:1.3.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "69BD64BB-BDA7-4F82-8324-B7C7C941133C" } ], "operator": "OR" } ] } ]