PT-2009-1050 · Kde+2 · Kdegraphics+3

Published

2009-04-16

·

Updated

2019-03-06

·

CVE-2009-0195

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Xpdf versions 3.02pl2 and earlier kdegraphics-devel versions 3.5.4 and earlier kdegraphics versions 3.5.4 and earlier
Description The issue allows remote attackers to execute arbitrary code via a crafted PDF file. Multiple vulnerabilities in the kdegraphics package can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For Xpdf versions 3.02pl2 and earlier, update to a version later than 3.02pl2 to resolve the issue. For kdegraphics-devel versions 3.5.4 and earlier, consider disabling the package until a patch is available. For kdegraphics versions 3.5.4 and earlier, restrict access to the package to minimize the risk of exploitation.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06216
BDU:2015-06220
BDU:2015-08480
BDU:2015-08481
CVE-2009-0195
DSA-1790-1
RHSA-2009:0429
RHSA-2009:0430
RHSA-2009:0431
RHSA-2009:0458
RHSA-2009:0480
RHSA-2009_0429
RHSA-2009_0430
RHSA-2009_0431
RHSA-2009_0458
RHSA-2009_0480
RHSA-2010:0399
RHSA-2010:0400
RHSA-2010_0399
RHSA-2010_0400

Affected Products

Red Hat
Xpdf
Kdegraphics
Kdegraphics-Devel