CVE Vulnerabilities

CVE-2009-3609

Published: Oct 21, 2009 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read.

Affected Software

Name Vendor Start Version End Version
Xpdf Foolabs 3.02pl1 (including) 3.02pl1 (including)
Xpdf Foolabs 3.02pl2 (including) 3.02pl2 (including)
Xpdf Foolabs 3.02pl3 (including) 3.02pl3 (including)
Xpdfreader Glyphandcog 3.00 (including) 3.00 (including)
Xpdfreader Glyphandcog 3.01 (including) 3.01 (including)
Xpdfreader Glyphandcog 3.02 (including) 3.02 (including)
Poppler Poppler * 0.12.0 (including)
Poppler Poppler 0.1 (including) 0.1 (including)
Poppler Poppler 0.1.1 (including) 0.1.1 (including)
Poppler Poppler 0.1.2 (including) 0.1.2 (including)
Poppler Poppler 0.2.0 (including) 0.2.0 (including)
Poppler Poppler 0.3.0 (including) 0.3.0 (including)
Poppler Poppler 0.3.1 (including) 0.3.1 (including)
Poppler Poppler 0.3.2 (including) 0.3.2 (including)
Poppler Poppler 0.3.3 (including) 0.3.3 (including)
Poppler Poppler 0.4.0 (including) 0.4.0 (including)
Poppler Poppler 0.4.1 (including) 0.4.1 (including)
Poppler Poppler 0.4.2 (including) 0.4.2 (including)
Poppler Poppler 0.4.3 (including) 0.4.3 (including)
Poppler Poppler 0.4.4 (including) 0.4.4 (including)
Poppler Poppler 0.5.0 (including) 0.5.0 (including)
Poppler Poppler 0.5.1 (including) 0.5.1 (including)
Poppler Poppler 0.5.2 (including) 0.5.2 (including)
Poppler Poppler 0.5.3 (including) 0.5.3 (including)
Poppler Poppler 0.5.4 (including) 0.5.4 (including)
Poppler Poppler 0.5.9 (including) 0.5.9 (including)
Poppler Poppler 0.6.0 (including) 0.6.0 (including)
Poppler Poppler 0.6.1 (including) 0.6.1 (including)
Poppler Poppler 0.6.2 (including) 0.6.2 (including)
Poppler Poppler 0.6.3 (including) 0.6.3 (including)
Poppler Poppler 0.6.4 (including) 0.6.4 (including)
Poppler Poppler 0.7.0 (including) 0.7.0 (including)
Poppler Poppler 0.7.1 (including) 0.7.1 (including)
Poppler Poppler 0.7.2 (including) 0.7.2 (including)
Poppler Poppler 0.7.3 (including) 0.7.3 (including)
Poppler Poppler 0.8.0 (including) 0.8.0 (including)
Poppler Poppler 0.8.1 (including) 0.8.1 (including)
Poppler Poppler 0.8.2 (including) 0.8.2 (including)
Poppler Poppler 0.8.3 (including) 0.8.3 (including)
Poppler Poppler 0.8.4 (including) 0.8.4 (including)
Poppler Poppler 0.8.6 (including) 0.8.6 (including)
Poppler Poppler 0.8.7 (including) 0.8.7 (including)
Poppler Poppler 0.9.0 (including) 0.9.0 (including)
Poppler Poppler 0.9.1 (including) 0.9.1 (including)
Poppler Poppler 0.9.2 (including) 0.9.2 (including)
Poppler Poppler 0.9.3 (including) 0.9.3 (including)
Poppler Poppler 0.10.0 (including) 0.10.0 (including)
Poppler Poppler 0.10.1 (including) 0.10.1 (including)
Poppler Poppler 0.10.2 (including) 0.10.2 (including)
Poppler Poppler 0.10.3 (including) 0.10.3 (including)
Poppler Poppler 0.10.4 (including) 0.10.4 (including)
Poppler Poppler 0.10.5 (including) 0.10.5 (including)
Poppler Poppler 0.10.6 (including) 0.10.6 (including)
Poppler Poppler 0.10.7 (including) 0.10.7 (including)
Poppler Poppler 0.11.0 (including) 0.11.0 (including)
Poppler Poppler 0.11.1 (including) 0.11.1 (including)
Poppler Poppler 0.11.2 (including) 0.11.2 (including)
Poppler Poppler 0.11.3 (including) 0.11.3 (including)

References