PT-2009-6726 · Xpdf+2 · Xpdf+2

Jan Lieskovsky

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2009-0146

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Xpdf versions 3.02pl2 and earlier CUPS versions 1.3.9 and earlier
Description The issue is related to multiple buffer overflows in the JBIG2 decoder, which can be exploited by remote attackers via a crafted PDF file. This can lead to a denial of service (crash) and potentially affect the confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations For Xpdf versions 3.02pl2 and earlier, update to a version later than 3.02pl2 to resolve the issue. For CUPS versions 1.3.9 and earlier, update to a version later than 1.3.9 to resolve the issue. As a temporary workaround, consider disabling the JBIG2 decoder in affected products until a patch is available. Restrict access to the JBIG2 decoder to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04161
BDU:2015-04162
BDU:2015-04163
BDU:2015-04164
BDU:2015-04165
BDU:2015-04166
BDU:2015-04167
BDU:2015-04168
BDU:2015-06216
BDU:2015-06220
BDU:2015-08480
BDU:2015-08481
BDU:2015-09375
CVE-2009-0146
DSA-1790-1
DSA-1793-1
OPENSUSE-SU-2024:10352-1
RHSA-2009:0429
RHSA-2009:0430
RHSA-2009:0431
RHSA-2009:0458
RHSA-2009:0480
RHSA-2009_0429
RHSA-2009_0430
RHSA-2009_0431
RHSA-2009_0458
RHSA-2009_0480
RHSA-2010:0399
RHSA-2010:0400
RHSA-2010_0399
RHSA-2010_0400

Affected Products

Cups
Red Hat
Xpdf