PT-2009-6639 · Apple+4 · Cups+5

Tomas Hoger

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2009-3609

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions cups-devel-1.1.22 versions 1.1.22 cups-libs-1.1.22 versions 1.1.22 cups-1.1.22 versions 1.1.22 libkscan-dev versions (affected versions not specified) kdegraphics-dev versions (affected versions not specified) xpdf-common versions (affected versions not specified) kviewshell versions (affected versions not specified) kdegraphics-dbg versions (affected versions not specified) kdegraphics-doc-html versions (affected versions not specified) kdvi versions (affected versions not specified) xpdf-reader versions (affected versions not specified) libkscan1 versions (affected versions not specified) kdegraphics versions (affected versions not specified) xpdf-utils versions (affected versions not specified) kdegraphics-kfile-plugins versions (affected versions not specified) Xpdf versions prior to 3.02pl4 Poppler versions prior to 0.12.1
Description The issue is related to multiple vulnerabilities in various packages, including libkscan-dev, kdegraphics-dev, cups-devel-1.1.22, cups-libs-1.1.22, cups-1.1.22, xpdf-common, kviewshell, kdegraphics-dbg, kdegraphics-doc-html, kdvi, xpdf-reader, libkscan1, kdegraphics, xpdf-utils, and kdegraphics-kfile-plugins. These vulnerabilities can be exploited remotely and may lead to a disruption of confidentiality, integrity, and availability of protected information. An integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1 can cause a denial of service (application crash) via a crafted PDF document.
Recommendations As a temporary workaround, consider disabling the ImageStream::ImageStream function until a patch is available. Restrict access to the vulnerable packages to minimize the risk of exploitation. Avoid using the vulnerable packages until the issue is resolved. Update Xpdf to version 3.02pl4 or later. Update Poppler to version 0.12.1 or later. At the moment, there is no information about a newer version that contains a fix for the other vulnerable packages.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00990
BDU:2015-00991
BDU:2015-00992
BDU:2015-00993
BDU:2015-00994
BDU:2015-00995
BDU:2015-00996
BDU:2015-00997
BDU:2015-00998
BDU:2015-02167
BDU:2015-02168
BDU:2015-02169
BDU:2015-06165
BDU:2015-06166
BDU:2015-06167
BDU:2015-08551
BDU:2015-08552
BDU:2015-08553
CVE-2009-3609
DSA-1941-1
DSA-2028-1
DSA-2050-1
RHSA-2009:1500
RHSA-2009:1501
RHSA-2009:1502
RHSA-2009:1503
RHSA-2009:1504
RHSA-2009:1512
RHSA-2009:1513
RHSA-2009_1501
RHSA-2009_1502
RHSA-2009_1503
RHSA-2009_1504
RHSA-2009_1512
RHSA-2009_1513
RHSA-2010:0399
RHSA-2010:0400
RHSA-2010:0401
RHSA-2010:0755
RHSA-2010_0399
RHSA-2010_0400
RHSA-2010_0755
USN-850-1
USN-850-3
USN-973-1

Affected Products

Poppler
Red Hat
Xpdf
Cups
Kdegraphics
Libkscan