PT-2009-6640 · Kde+4 · Kdegraphics-Doc-Html+15

Tomas Hoger

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2009-1188

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions kdegraphics versions prior to 3.02pl4 libkscan-dev (affected versions not specified) kdegraphics-dev (affected versions not specified) xpdf-common (affected versions not specified) kviewshell (affected versions not specified) kdegraphics-dbg (affected versions not specified) kdegraphics-doc-html (affected versions not specified) kdvi (affected versions not specified) xpdf-reader (affected versions not specified) libkscan1 (affected versions not specified) xpdf-utils (affected versions not specified) kdegraphics (affected versions not specified) kdegraphics-kfile-plugins (affected versions not specified) Poppler versions prior to 0.10.6
Description The issue is related to multiple vulnerabilities in various packages of the Debian GNU/Linux operating system, including kdegraphics, libkscan-dev, and xpdf-common, among others. These vulnerabilities can lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be carried out remotely. Specifically, an integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted PDF document.
Recommendations For kdegraphics versions prior to 3.02pl4, update to version 3.02pl4 or later. For Poppler versions prior to 0.10.6, update to version 0.10.6 or later. For other affected packages, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00990
BDU:2015-00991
BDU:2015-00992
BDU:2015-00993
BDU:2015-00994
BDU:2015-00995
BDU:2015-00996
BDU:2015-00997
BDU:2015-00998
BDU:2015-02167
BDU:2015-02168
BDU:2015-02169
CVE-2009-1188
DSA-2028-1
DSA-2050-1
OPENSUSE-SU-2024:10360-1
RHSA-2009:0480
RHSA-2009:1501
RHSA-2009:1502
RHSA-2009:1503
RHSA-2009:1512
RHSA-2009_0480
RHSA-2009_1501
RHSA-2009_1502
RHSA-2009_1503
RHSA-2009_1512

Affected Products

Debian
Poppler
Red Hat
Xpdf
Kdegraphics
Kdegraphics-Dbg
Kdegraphics-Devel
Kdegraphics-Doc-Html
Kdegraphics-Kfile-Plugins
Kdvi
Kviewshell
Libkscan-Dev
Libkscan1
Xpdf-Common
Xpdf-Reader
Xpdf-Utils