CVE Vulnerabilities

CVE-2009-3603

Published: Oct 21, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.

Affected Software

NameVendorStart VersionEnd Version
XpdfFoolabs3.02pl1 (including)3.02pl1 (including)
XpdfFoolabs3.02pl2 (including)3.02pl2 (including)
XpdfFoolabs3.02pl3 (including)3.02pl3 (including)
XpdfreaderGlyphandcog3.00 (including)3.00 (including)
XpdfreaderGlyphandcog3.01 (including)3.01 (including)
XpdfreaderGlyphandcog3.02 (including)3.02 (including)
PopplerPoppler*0.12.0 (including)
PopplerPoppler0.1 (including)0.1 (including)
PopplerPoppler0.1.1 (including)0.1.1 (including)
PopplerPoppler0.1.2 (including)0.1.2 (including)
PopplerPoppler0.2.0 (including)0.2.0 (including)
PopplerPoppler0.3.0 (including)0.3.0 (including)
PopplerPoppler0.3.1 (including)0.3.1 (including)
PopplerPoppler0.3.2 (including)0.3.2 (including)
PopplerPoppler0.3.3 (including)0.3.3 (including)
PopplerPoppler0.4.0 (including)0.4.0 (including)
PopplerPoppler0.4.1 (including)0.4.1 (including)
PopplerPoppler0.4.2 (including)0.4.2 (including)
PopplerPoppler0.4.3 (including)0.4.3 (including)
PopplerPoppler0.4.4 (including)0.4.4 (including)
PopplerPoppler0.5.0 (including)0.5.0 (including)
PopplerPoppler0.5.1 (including)0.5.1 (including)
PopplerPoppler0.5.2 (including)0.5.2 (including)
PopplerPoppler0.5.3 (including)0.5.3 (including)
PopplerPoppler0.5.4 (including)0.5.4 (including)
PopplerPoppler0.5.9 (including)0.5.9 (including)
PopplerPoppler0.6.0 (including)0.6.0 (including)
PopplerPoppler0.6.1 (including)0.6.1 (including)
PopplerPoppler0.6.2 (including)0.6.2 (including)
PopplerPoppler0.6.3 (including)0.6.3 (including)
PopplerPoppler0.6.4 (including)0.6.4 (including)
PopplerPoppler0.7.0 (including)0.7.0 (including)
PopplerPoppler0.7.1 (including)0.7.1 (including)
PopplerPoppler0.7.2 (including)0.7.2 (including)
PopplerPoppler0.7.3 (including)0.7.3 (including)
PopplerPoppler0.8.0 (including)0.8.0 (including)
PopplerPoppler0.8.1 (including)0.8.1 (including)
PopplerPoppler0.8.2 (including)0.8.2 (including)
PopplerPoppler0.8.3 (including)0.8.3 (including)
PopplerPoppler0.8.4 (including)0.8.4 (including)
PopplerPoppler0.8.6 (including)0.8.6 (including)
PopplerPoppler0.8.7 (including)0.8.7 (including)
PopplerPoppler0.9.0 (including)0.9.0 (including)
PopplerPoppler0.9.1 (including)0.9.1 (including)
PopplerPoppler0.9.2 (including)0.9.2 (including)
PopplerPoppler0.9.3 (including)0.9.3 (including)
PopplerPoppler0.10.0 (including)0.10.0 (including)
PopplerPoppler0.10.1 (including)0.10.1 (including)
PopplerPoppler0.10.2 (including)0.10.2 (including)
PopplerPoppler0.10.3 (including)0.10.3 (including)
PopplerPoppler0.10.4 (including)0.10.4 (including)
PopplerPoppler0.10.5 (including)0.10.5 (including)
PopplerPoppler0.10.6 (including)0.10.6 (including)
PopplerPoppler0.10.7 (including)0.10.7 (including)
PopplerPoppler0.11.0 (including)0.11.0 (including)
PopplerPoppler0.11.1 (including)0.11.1 (including)
PopplerPoppler0.11.2 (including)0.11.2 (including)
PopplerPoppler0.11.3 (including)0.11.3 (including)
Red Hat Enterprise Linux 5RedHatpoppler-0:0.5.4-4.4.el5_4.11*
GpdfUbuntudapper*
IpeUbuntuartful*
IpeUbuntubionic*
IpeUbuntucosmic*
IpeUbuntudapper*
IpeUbuntudisco*
IpeUbuntueoan*
IpeUbuntufocal*
IpeUbuntugroovy*
IpeUbuntuhardy*
IpeUbuntuhirsute*
IpeUbuntuimpish*
IpeUbuntuintrepid*
IpeUbuntujaunty*
IpeUbuntukarmic*
IpeUbuntukinetic*
IpeUbuntulucid*
IpeUbuntulunar*
IpeUbuntumantic*
IpeUbuntumaverick*
IpeUbuntunatty*
IpeUbuntuoneiric*
IpeUbuntuoracular*
IpeUbuntuplucky*
IpeUbuntuprecise*
IpeUbuntuquantal*
IpeUbunturaring*
IpeUbuntusaucy*
IpeUbuntutrusty*
IpeUbuntuutopic*
IpeUbuntuvivid*
IpeUbuntuwily*
IpeUbuntuxenial*
IpeUbuntuyakkety*
IpeUbuntuzesty*
KofficeUbuntudapper*
LibextractorUbuntuartful*
LibextractorUbuntucosmic*
LibextractorUbuntudapper*
LibextractorUbuntudisco*
LibextractorUbuntueoan*
LibextractorUbuntugroovy*
LibextractorUbuntuhardy*
LibextractorUbuntuhirsute*
LibextractorUbuntuimpish*
LibextractorUbuntuintrepid*
LibextractorUbuntujaunty*
LibextractorUbuntukarmic*
LibextractorUbuntulucid*
LibextractorUbuntumaverick*
LibextractorUbuntunatty*
LibextractorUbuntuoneiric*
LibextractorUbuntuprecise*
LibextractorUbuntuquantal*
LibextractorUbunturaring*
LibextractorUbuntusaucy*
LibextractorUbuntutrusty*
LibextractorUbuntuutopic*
LibextractorUbuntuvivid*
LibextractorUbuntuwily*
LibextractorUbuntuxenial*
LibextractorUbuntuyakkety*
LibextractorUbuntuzesty*
Pdfkit.frameworkUbuntudapper*
PdftohtmlUbuntudapper*
PopplerUbuntuartful*
PopplerUbuntubionic*
PopplerUbuntucosmic*
PopplerUbuntudapper*
PopplerUbuntudevel*
PopplerUbuntudisco*
PopplerUbuntueoan*
PopplerUbuntuesm-infra/bionic*
PopplerUbuntuesm-infra/focal*
PopplerUbuntuesm-infra/xenial*
PopplerUbuntufocal*
PopplerUbuntugroovy*
PopplerUbuntuhardy*
PopplerUbuntuhirsute*
PopplerUbuntuimpish*
PopplerUbuntuintrepid*
PopplerUbuntujammy*
PopplerUbuntujaunty*
PopplerUbuntukarmic*
PopplerUbuntukinetic*
PopplerUbuntulucid*
PopplerUbuntulunar*
PopplerUbuntumantic*
PopplerUbuntumaverick*
PopplerUbuntunatty*
PopplerUbuntunoble*
PopplerUbuntuoneiric*
PopplerUbuntuoracular*
PopplerUbuntuplucky*
PopplerUbuntuprecise*
PopplerUbuntuquantal*
PopplerUbuntuquesting*
PopplerUbunturaring*
PopplerUbuntusaucy*
PopplerUbuntutrusty*
PopplerUbuntuutopic*
PopplerUbuntuvivid*
PopplerUbuntuvivid/stable-phone-overlay*
PopplerUbuntuwily*
PopplerUbuntuxenial*
PopplerUbuntuyakkety*
PopplerUbuntuzesty*
XpdfUbuntudapper*
XpdfUbuntuhardy*
XpdfUbuntuintrepid*
XpdfUbuntujaunty*
XpdfUbuntukarmic*
XpdfUbuntuupstream*

References