PT-2009-3396 · Apple+3 · Cups+3

Jan Lieskovsky

·

Published

2009-05-13

·

Updated

2023-02-13

·

CVE-2009-0791

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CUPS versions 1.1.17 through 1.1.22 CUPS version 1.3.7 Xpdf versions 2.x through 3.x Poppler version 0.x
Description The issue is related to multiple integer overflows in the pdftops filter, which can be exploited by remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted PDF file. This can trigger a heap-based buffer overflow, potentially related to files such as Decrypt.cxx, FoFiTrueType.cxx, gmem.c, JBIG2Stream.cxx, and PSOutputDev.cxx in pdftops.
Recommendations For CUPS versions 1.1.17 through 1.1.22, consider updating to a version that includes a fix for the integer overflows in the pdftops filter. For CUPS version 1.3.7, consider updating to a version that includes a fix for the integer overflows in the pdftops filter. For Xpdf versions 2.x through 3.x, consider updating to a version that includes a fix for the integer overflows. For Poppler version 0.x, consider updating to a version that includes a fix for the integer overflows. As a temporary workaround, consider disabling the use of the pdftops filter until a patch is available.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2009-0791
RHSA-2009:0480
RHSA-2009:1083
RHSA-2009:1500
RHSA-2009:1501
RHSA-2009:1502
RHSA-2009:1503
RHSA-2009:1512
RHSA-2009_0480
RHSA-2009_1083
RHSA-2009_1501
RHSA-2009_1502
RHSA-2009_1503
RHSA-2009_1512
RHSA-2010:0399
RHSA-2010:0400
RHSA-2010:0401
RHSA-2010_0399
RHSA-2010_0400

Affected Products

Cups
Poppler
Red Hat
Xpdf