PT-2009-6726 · Xpdf+2 · Xpdf+2
Jan Lieskovsky
·
Publicado
1970-01-01
·
Atualizado
2024-06-15
·
CVE-2009-0146
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Xpdf versions 3.02pl2 and earlier
CUPS versions 1.3.9 and earlier
Description
The issue is related to multiple buffer overflows in the JBIG2 decoder, which can be exploited by remote attackers via a crafted PDF file. This can lead to a denial of service (crash) and potentially affect the confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations
For Xpdf versions 3.02pl2 and earlier, update to a version later than 3.02pl2 to resolve the issue.
For CUPS versions 1.3.9 and earlier, update to a version later than 1.3.9 to resolve the issue.
As a temporary workaround, consider disabling the JBIG2 decoder in affected products until a patch is available.
Restrict access to the JBIG2 decoder to minimize the risk of exploitation.
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cups
Red Hat
Xpdf