PT-2009-6726 · Xpdf+2 · Xpdf+2
Jan Lieskovsky
·
Published
1970-01-01
·
Updated
2024-06-15
·
CVE-2009-0146
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Xpdf versions 3.02pl2 and earlier
CUPS versions 1.3.9 and earlier
Description
The issue is related to multiple buffer overflows in the JBIG2 decoder, which can be exploited by remote attackers via a crafted PDF file. This can lead to a denial of service (crash) and potentially affect the confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations
For Xpdf versions 3.02pl2 and earlier, update to a version later than 3.02pl2 to resolve the issue.
For CUPS versions 1.3.9 and earlier, update to a version later than 1.3.9 to resolve the issue.
As a temporary workaround, consider disabling the JBIG2 decoder in affected products until a patch is available.
Restrict access to the JBIG2 decoder to minimize the risk of exploitation.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cups
Red Hat
Xpdf