CVE Vulnerabilities

CVE-2009-3608

Published: Oct 21, 2009 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Xpdf Foolabs 3.02pl1 (including) 3.02pl1 (including)
Xpdf Foolabs 3.02pl2 (including) 3.02pl2 (including)
Xpdf Foolabs 3.02pl3 (including) 3.02pl3 (including)
Xpdfreader Glyphandcog 3.00 (including) 3.00 (including)
Xpdfreader Glyphandcog 3.01 (including) 3.01 (including)
Xpdfreader Glyphandcog 3.02 (including) 3.02 (including)
Poppler Poppler * 0.12.0 (including)
Poppler Poppler 0.1 (including) 0.1 (including)
Poppler Poppler 0.1.1 (including) 0.1.1 (including)
Poppler Poppler 0.1.2 (including) 0.1.2 (including)
Poppler Poppler 0.2.0 (including) 0.2.0 (including)
Poppler Poppler 0.3.0 (including) 0.3.0 (including)
Poppler Poppler 0.3.1 (including) 0.3.1 (including)
Poppler Poppler 0.3.2 (including) 0.3.2 (including)
Poppler Poppler 0.3.3 (including) 0.3.3 (including)
Poppler Poppler 0.4.0 (including) 0.4.0 (including)
Poppler Poppler 0.4.1 (including) 0.4.1 (including)
Poppler Poppler 0.4.2 (including) 0.4.2 (including)
Poppler Poppler 0.4.3 (including) 0.4.3 (including)
Poppler Poppler 0.4.4 (including) 0.4.4 (including)
Poppler Poppler 0.5.0 (including) 0.5.0 (including)
Poppler Poppler 0.5.1 (including) 0.5.1 (including)
Poppler Poppler 0.5.2 (including) 0.5.2 (including)
Poppler Poppler 0.5.3 (including) 0.5.3 (including)
Poppler Poppler 0.5.4 (including) 0.5.4 (including)
Poppler Poppler 0.5.9 (including) 0.5.9 (including)
Poppler Poppler 0.6.0 (including) 0.6.0 (including)
Poppler Poppler 0.6.1 (including) 0.6.1 (including)
Poppler Poppler 0.6.2 (including) 0.6.2 (including)
Poppler Poppler 0.6.3 (including) 0.6.3 (including)
Poppler Poppler 0.6.4 (including) 0.6.4 (including)
Poppler Poppler 0.7.0 (including) 0.7.0 (including)
Poppler Poppler 0.7.1 (including) 0.7.1 (including)
Poppler Poppler 0.7.2 (including) 0.7.2 (including)
Poppler Poppler 0.7.3 (including) 0.7.3 (including)
Poppler Poppler 0.8.0 (including) 0.8.0 (including)
Poppler Poppler 0.8.1 (including) 0.8.1 (including)
Poppler Poppler 0.8.2 (including) 0.8.2 (including)
Poppler Poppler 0.8.3 (including) 0.8.3 (including)
Poppler Poppler 0.8.4 (including) 0.8.4 (including)
Poppler Poppler 0.8.6 (including) 0.8.6 (including)
Poppler Poppler 0.8.7 (including) 0.8.7 (including)
Poppler Poppler 0.9.0 (including) 0.9.0 (including)
Poppler Poppler 0.9.1 (including) 0.9.1 (including)
Poppler Poppler 0.9.2 (including) 0.9.2 (including)
Poppler Poppler 0.9.3 (including) 0.9.3 (including)
Poppler Poppler 0.10.0 (including) 0.10.0 (including)
Poppler Poppler 0.10.1 (including) 0.10.1 (including)
Poppler Poppler 0.10.2 (including) 0.10.2 (including)
Poppler Poppler 0.10.3 (including) 0.10.3 (including)
Poppler Poppler 0.10.4 (including) 0.10.4 (including)
Poppler Poppler 0.10.5 (including) 0.10.5 (including)
Poppler Poppler 0.10.6 (including) 0.10.6 (including)
Poppler Poppler 0.10.7 (including) 0.10.7 (including)
Poppler Poppler 0.11.0 (including) 0.11.0 (including)
Poppler Poppler 0.11.1 (including) 0.11.1 (including)
Poppler Poppler 0.11.2 (including) 0.11.2 (including)
Poppler Poppler 0.11.3 (including) 0.11.3 (including)
Red Hat Enterprise Linux 4 RedHat xpdf-1:3.00-22.el4_8.1 *
Red Hat Enterprise Linux 4 RedHat gpdf-0:2.8.2-7.7.2.el4_8.5 *
Red Hat Enterprise Linux 4 RedHat kdegraphics-7:3.3.1-15.el4_8.2 *
Red Hat Enterprise Linux 5 RedHat kdegraphics-7:3.5.4-15.el5_4.2 *
Red Hat Enterprise Linux 5 RedHat poppler-0:0.5.4-4.4.el5_4.11 *
Red Hat Enterprise Linux 5 RedHat cups-1:1.3.7-11.el5_4.3 *
Red Hat Enterprise Linux 5 RedHat tetex-0:3.0-33.8.el5_5.5 *
Gpdf Ubuntu dapper *
Ipe Ubuntu artful *
Ipe Ubuntu bionic *
Ipe Ubuntu cosmic *
Ipe Ubuntu dapper *
Ipe Ubuntu disco *
Ipe Ubuntu eoan *
Ipe Ubuntu groovy *
Ipe Ubuntu hardy *
Ipe Ubuntu hirsute *
Ipe Ubuntu impish *
Ipe Ubuntu intrepid *
Ipe Ubuntu jaunty *
Ipe Ubuntu karmic *
Ipe Ubuntu kinetic *
Ipe Ubuntu lucid *
Ipe Ubuntu lunar *
Ipe Ubuntu mantic *
Ipe Ubuntu maverick *
Ipe Ubuntu natty *
Ipe Ubuntu oneiric *
Ipe Ubuntu precise *
Ipe Ubuntu quantal *
Ipe Ubuntu raring *
Ipe Ubuntu saucy *
Ipe Ubuntu trusty *
Ipe Ubuntu utopic *
Ipe Ubuntu vivid *
Ipe Ubuntu wily *
Ipe Ubuntu xenial *
Ipe Ubuntu yakkety *
Ipe Ubuntu zesty *
Koffice Ubuntu dapper *
Koffice Ubuntu hardy *
Koffice Ubuntu intrepid *
Koffice Ubuntu jaunty *
Libextractor Ubuntu artful *
Libextractor Ubuntu cosmic *
Libextractor Ubuntu dapper *
Libextractor Ubuntu disco *
Libextractor Ubuntu eoan *
Libextractor Ubuntu groovy *
Libextractor Ubuntu hardy *
Libextractor Ubuntu hirsute *
Libextractor Ubuntu impish *
Libextractor Ubuntu intrepid *
Libextractor Ubuntu jaunty *
Libextractor Ubuntu karmic *
Libextractor Ubuntu lucid *
Libextractor Ubuntu maverick *
Libextractor Ubuntu natty *
Libextractor Ubuntu oneiric *
Libextractor Ubuntu precise *
Libextractor Ubuntu quantal *
Libextractor Ubuntu raring *
Libextractor Ubuntu saucy *
Libextractor Ubuntu trusty *
Libextractor Ubuntu utopic *
Libextractor Ubuntu vivid *
Libextractor Ubuntu wily *
Libextractor Ubuntu xenial *
Libextractor Ubuntu yakkety *
Libextractor Ubuntu zesty *
Pdfkit.framework Ubuntu dapper *
Pdftohtml Ubuntu dapper *
Poppler Ubuntu artful *
Poppler Ubuntu bionic *
Poppler Ubuntu cosmic *
Poppler Ubuntu dapper *
Poppler Ubuntu devel *
Poppler Ubuntu disco *
Poppler Ubuntu eoan *
Poppler Ubuntu focal *
Poppler Ubuntu groovy *
Poppler Ubuntu hardy *
Poppler Ubuntu hirsute *
Poppler Ubuntu impish *
Poppler Ubuntu intrepid *
Poppler Ubuntu jammy *
Poppler Ubuntu jaunty *
Poppler Ubuntu karmic *
Poppler Ubuntu kinetic *
Poppler Ubuntu lucid *
Poppler Ubuntu lunar *
Poppler Ubuntu mantic *
Poppler Ubuntu maverick *
Poppler Ubuntu natty *
Poppler Ubuntu noble *
Poppler Ubuntu oneiric *
Poppler Ubuntu oracular *
Poppler Ubuntu precise *
Poppler Ubuntu quantal *
Poppler Ubuntu raring *
Poppler Ubuntu saucy *
Poppler Ubuntu trusty *
Poppler Ubuntu utopic *
Poppler Ubuntu vivid *
Poppler Ubuntu vivid/stable-phone-overlay *
Poppler Ubuntu wily *
Poppler Ubuntu xenial *
Poppler Ubuntu yakkety *
Poppler Ubuntu zesty *
Xpdf Ubuntu dapper *
Xpdf Ubuntu hardy *
Xpdf Ubuntu intrepid *
Xpdf Ubuntu jaunty *
Xpdf Ubuntu karmic *
Xpdf Ubuntu upstream *

References