PT-2009-6643 · Debian+2 · Kdegraphics-Doc-Html+15

Tomas Hoger

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2009-3606

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions kdegraphics-dev (affected versions not specified) kdegraphics-dbg (affected versions not specified) kdegraphics-doc-html (affected versions not specified) kdvi (affected versions not specified) kdegraphics (affected versions not specified) kdegraphics-kfile-plugins (affected versions not specified) libkscan-dev (affected versions not specified) libkscan1 (affected versions not specified) kviewshell (affected versions not specified) xpdf-common (affected versions not specified) xpdf-reader (affected versions not specified) xpdf-utils (affected versions not specified) Xpdf versions prior to 3.02pl4 Poppler 0.x
Description The issue involves multiple vulnerabilities in various packages of the Debian GNU/Linux operating system, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, an integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4 and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
Recommendations As a temporary workaround, consider disabling the PSOutputDev::doImageL1Sep function until a patch is available. Restrict access to the vulnerable packages to minimize the risk of exploitation. Avoid using the affected packages until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

BDU:2015-00990
BDU:2015-00991
BDU:2015-00992
BDU:2015-00993
BDU:2015-00994
BDU:2015-00995
BDU:2015-00996
BDU:2015-00997
BDU:2015-00998
BDU:2015-02167
BDU:2015-02168
BDU:2015-02169
CVE-2009-3606
DSA-1941-1
DSA-2028-1
DSA-2050-1
RHSA-2009:0458
RHSA-2009:0480
RHSA-2009:1500
RHSA-2009:1501
RHSA-2009:1502
RHSA-2009_0458
RHSA-2009_0480
RHSA-2009_1501
RHSA-2009_1502
USN-973-1

Affected Products

Kpdf
Poppler
Red Hat
Xpdf
Kdegraphics
Kdegraphics-Dbg
Kdegraphics-Devel
Kdegraphics-Doc-Html
Kdegraphics-Kfile-Plugins
Kdvi
Kviewshell
Libkscan-Dev
Libkscan1
Xpdf-Common
Xpdf-Reader
Xpdf-Utils