CVE Vulnerabilities

CVE-2009-3606

Published: Oct 21, 2009 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
3.7 MODERATE
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Xpdf Foolabs 3.02pl1 (including) 3.02pl1 (including)
Xpdf Foolabs 3.02pl2 (including) 3.02pl2 (including)
Xpdf Foolabs 3.02pl3 (including) 3.02pl3 (including)
Xpdfreader Glyphandcog 3.00 (including) 3.00 (including)
Xpdfreader Glyphandcog 3.01 (including) 3.01 (including)
Xpdfreader Glyphandcog 3.02 (including) 3.02 (including)
Poppler Poppler 0.1 (including) 0.1 (including)
Poppler Poppler 0.1.1 (including) 0.1.1 (including)
Poppler Poppler 0.1.2 (including) 0.1.2 (including)
Poppler Poppler 0.2.0 (including) 0.2.0 (including)
Poppler Poppler 0.3.0 (including) 0.3.0 (including)
Poppler Poppler 0.3.1 (including) 0.3.1 (including)
Poppler Poppler 0.3.2 (including) 0.3.2 (including)
Poppler Poppler 0.3.3 (including) 0.3.3 (including)
Poppler Poppler 0.4.0 (including) 0.4.0 (including)
Poppler Poppler 0.4.1 (including) 0.4.1 (including)
Poppler Poppler 0.4.2 (including) 0.4.2 (including)
Poppler Poppler 0.4.3 (including) 0.4.3 (including)
Poppler Poppler 0.4.4 (including) 0.4.4 (including)
Poppler Poppler 0.5.0 (including) 0.5.0 (including)
Poppler Poppler 0.5.1 (including) 0.5.1 (including)
Poppler Poppler 0.5.2 (including) 0.5.2 (including)
Poppler Poppler 0.5.3 (including) 0.5.3 (including)
Poppler Poppler 0.5.4 (including) 0.5.4 (including)
Poppler Poppler 0.5.9 (including) 0.5.9 (including)
Poppler Poppler 0.6.0 (including) 0.6.0 (including)
Poppler Poppler 0.6.1 (including) 0.6.1 (including)
Poppler Poppler 0.6.2 (including) 0.6.2 (including)
Poppler Poppler 0.6.3 (including) 0.6.3 (including)
Poppler Poppler 0.6.4 (including) 0.6.4 (including)
Poppler Poppler 0.7.0 (including) 0.7.0 (including)
Poppler Poppler 0.7.1 (including) 0.7.1 (including)
Poppler Poppler 0.7.2 (including) 0.7.2 (including)
Poppler Poppler 0.7.3 (including) 0.7.3 (including)
Poppler Poppler 0.8.0 (including) 0.8.0 (including)
Poppler Poppler 0.8.1 (including) 0.8.1 (including)
Poppler Poppler 0.8.2 (including) 0.8.2 (including)
Poppler Poppler 0.8.3 (including) 0.8.3 (including)
Poppler Poppler 0.8.4 (including) 0.8.4 (including)
Poppler Poppler 0.8.6 (including) 0.8.6 (including)
Poppler Poppler 0.8.7 (including) 0.8.7 (including)
Poppler Poppler 0.9.0 (including) 0.9.0 (including)
Poppler Poppler 0.9.1 (including) 0.9.1 (including)
Poppler Poppler 0.9.2 (including) 0.9.2 (including)
Poppler Poppler 0.9.3 (including) 0.9.3 (including)
Poppler Poppler 0.10.0 (including) 0.10.0 (including)
Poppler Poppler 0.10.1 (including) 0.10.1 (including)
Poppler Poppler 0.10.2 (including) 0.10.2 (including)
Poppler Poppler 0.10.3 (including) 0.10.3 (including)
Poppler Poppler 0.10.4 (including) 0.10.4 (including)
Poppler Poppler 0.10.5 (including) 0.10.5 (including)
Poppler Poppler 0.10.6 (including) 0.10.6 (including)
Poppler Poppler 0.10.7 (including) 0.10.7 (including)
Poppler Poppler 0.11.0 (including) 0.11.0 (including)
Poppler Poppler 0.11.1 (including) 0.11.1 (including)
Poppler Poppler 0.11.2 (including) 0.11.2 (including)
Poppler Poppler 0.11.3 (including) 0.11.3 (including)
Poppler Poppler 0.12.0 (including) 0.12.0 (including)
Red Hat Enterprise Linux 3 RedHat xpdf-1:2.02-17.el3 *
Red Hat Enterprise Linux 4 RedHat gpdf-0:2.8.2-7.7.2.el4_7.4 *
Red Hat Enterprise Linux 4 RedHat xpdf-1:3.00-22.el4_8.1 *
Red Hat Enterprise Linux 5 RedHat poppler-0:0.5.4-4.4.el5_3.9 *
Red Hat Enterprise Linux 5 RedHat kdegraphics-7:3.5.4-15.el5_4.2 *
Gpdf Ubuntu dapper *
Ipe Ubuntu artful *
Ipe Ubuntu bionic *
Ipe Ubuntu cosmic *
Ipe Ubuntu dapper *
Ipe Ubuntu disco *
Ipe Ubuntu eoan *
Ipe Ubuntu groovy *
Ipe Ubuntu hardy *
Ipe Ubuntu hirsute *
Ipe Ubuntu impish *
Ipe Ubuntu intrepid *
Ipe Ubuntu jaunty *
Ipe Ubuntu karmic *
Ipe Ubuntu kinetic *
Ipe Ubuntu lucid *
Ipe Ubuntu lunar *
Ipe Ubuntu mantic *
Ipe Ubuntu maverick *
Ipe Ubuntu natty *
Ipe Ubuntu oneiric *
Ipe Ubuntu precise *
Ipe Ubuntu quantal *
Ipe Ubuntu raring *
Ipe Ubuntu saucy *
Ipe Ubuntu trusty *
Ipe Ubuntu utopic *
Ipe Ubuntu vivid *
Ipe Ubuntu wily *
Ipe Ubuntu xenial *
Ipe Ubuntu yakkety *
Ipe Ubuntu zesty *
Koffice Ubuntu dapper *
Koffice Ubuntu hardy *
Koffice Ubuntu intrepid *
Koffice Ubuntu jaunty *
Libextractor Ubuntu artful *
Libextractor Ubuntu cosmic *
Libextractor Ubuntu dapper *
Libextractor Ubuntu disco *
Libextractor Ubuntu eoan *
Libextractor Ubuntu groovy *
Libextractor Ubuntu hardy *
Libextractor Ubuntu hirsute *
Libextractor Ubuntu impish *
Libextractor Ubuntu intrepid *
Libextractor Ubuntu jaunty *
Libextractor Ubuntu karmic *
Libextractor Ubuntu lucid *
Libextractor Ubuntu maverick *
Libextractor Ubuntu natty *
Libextractor Ubuntu oneiric *
Libextractor Ubuntu precise *
Libextractor Ubuntu quantal *
Libextractor Ubuntu raring *
Libextractor Ubuntu saucy *
Libextractor Ubuntu trusty *
Libextractor Ubuntu utopic *
Libextractor Ubuntu vivid *
Libextractor Ubuntu wily *
Libextractor Ubuntu xenial *
Libextractor Ubuntu yakkety *
Libextractor Ubuntu zesty *
Pdfkit.framework Ubuntu dapper *
Pdftohtml Ubuntu dapper *
Poppler Ubuntu dapper *
Poppler Ubuntu hardy *
Poppler Ubuntu intrepid *
Poppler Ubuntu jaunty *
Xpdf Ubuntu dapper *
Xpdf Ubuntu hardy *
Xpdf Ubuntu intrepid *
Xpdf Ubuntu jaunty *
Xpdf Ubuntu karmic *
Xpdf Ubuntu upstream *

References