PT-2009-3396 · Apple+3 · Cups+3
Jan Lieskovsky
·
Published
2009-05-13
·
Updated
2023-02-13
·
CVE-2009-0791
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CUPS versions 1.1.17 through 1.1.22
CUPS version 1.3.7
Xpdf versions 2.x through 3.x
Poppler version 0.x
Description
The issue is related to multiple integer overflows in the pdftops filter, which can be exploited by remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted PDF file. This can trigger a heap-based buffer overflow, potentially related to files such as
Decrypt.cxx, FoFiTrueType.cxx, gmem.c, JBIG2Stream.cxx, and PSOutputDev.cxx in pdftops.Recommendations
For CUPS versions 1.1.17 through 1.1.22, consider updating to a version that includes a fix for the integer overflows in the pdftops filter.
For CUPS version 1.3.7, consider updating to a version that includes a fix for the integer overflows in the pdftops filter.
For Xpdf versions 2.x through 3.x, consider updating to a version that includes a fix for the integer overflows.
For Poppler version 0.x, consider updating to a version that includes a fix for the integer overflows.
As a temporary workaround, consider disabling the use of the pdftops filter until a patch is available.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cups
Poppler
Red Hat
Xpdf