CVE-2009-0195
xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)
Severity Score
7.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.
Desbordamiento de búfer basado en montículo en Xpdf v3.02p12 y anteriores, CUPS v1.3.9 y probablemente otros productos, permite a atacantes remotos ejecutar código de forma arbitraria a través de un fichero PDF con segmentos JBIG2 de diccionario simbólico manipulados.
Multiple vulnerabilities have been found in Poppler, some of which may allow execution of arbitrary code. Versions less than 0.22.2-r1 are affected.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2009-01-20 CVE Reserved
- 2009-04-23 CVE Published
- 2024-08-07 CVE Updated
- 2025-04-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (17)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/34291 | Third Party Advisory | |
http://secunia.com/advisories/34481 | Third Party Advisory | |
http://secunia.com/advisories/34756 | Third Party Advisory | |
http://secunia.com/advisories/34963 | Third Party Advisory | |
http://secunia.com/advisories/35064 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/502759/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/502762/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/34791 | Vdb Entry | |
http://www.vupen.com/english/advisories/2010/1040 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10076 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2009-0458.html | 2019-03-06 | |
http://secunia.com/secunia_research/2009-17 | 2019-03-06 | |
http://secunia.com/secunia_research/2009-18 | 2019-03-06 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2010:087 | 2019-03-06 | |
http://www.redhat.com/support/errata/RHSA-2009-0480.html | 2019-03-06 | |
https://access.redhat.com/security/cve/CVE-2009-0195 | 2010-05-06 | |
https://bugzilla.redhat.com/show_bug.cgi?id=490612 | 2010-05-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Cups Search vendor "Apple" for product "Cups" | 1.3.9 Search vendor "Apple" for product "Cups" and version "1.3.9" | - |
Affected
| ||||||
Foolabs Search vendor "Foolabs" | Xpdf Search vendor "Foolabs" for product "Xpdf" | 0.5a Search vendor "Foolabs" for product "Xpdf" and version "0.5a" | - |
Affected
| ||||||
Foolabs Search vendor "Foolabs" | Xpdf Search vendor "Foolabs" for product "Xpdf" | 0.7a Search vendor "Foolabs" for product "Xpdf" and version "0.7a" | - |
Affected
| ||||||
Foolabs Search vendor "Foolabs" | Xpdf Search vendor "Foolabs" for product "Xpdf" | 0.91a Search vendor "Foolabs" for product "Xpdf" and version "0.91a" | - |
Affected
| ||||||
Foolabs Search vendor "Foolabs" | Xpdf Search vendor "Foolabs" for product "Xpdf" | 0.91b Search vendor "Foolabs" for product "Xpdf" and version "0.91b" | - |
Affected
| ||||||
Foolabs Search vendor "Foolabs" | Xpdf Search vendor "Foolabs" for product "Xpdf" | 0.91c Search vendor "Foolabs" for product "Xpdf" and version "0.91c" | - |
Affected
| ||||||
Foolabs Search vendor "Foolabs" | Xpdf Search vendor "Foolabs" for product "Xpdf" | 0.92a Search vendor "Foolabs" for product "Xpdf" and version "0.92a" | - |
Affected
| ||||||
Foolabs Search vendor "Foolabs" | Xpdf Search vendor "Foolabs" for product "Xpdf" | 0.92b Search vendor "Foolabs" for product "Xpdf" and version "0.92b" | - |
Affected
| ||||||
Foolabs Search vendor "Foolabs" | Xpdf Search vendor "Foolabs" for product "Xpdf" | 0.92c Search vendor "Foolabs" for product "Xpdf" and version "0.92c" | - |
Affected
| ||||||
Foolabs Search vendor "Foolabs" | Xpdf Search vendor "Foolabs" for product "Xpdf" | 0.92d Search vendor "Foolabs" for product "Xpdf" and version "0.92d" | - |
Affected
| ||||||
Foolabs Search vendor "Foolabs" | Xpdf Search vendor "Foolabs" for product "Xpdf" | 0.92e Search vendor "Foolabs" for product "Xpdf" and version "0.92e" | - |
Affected
| ||||||
Foolabs Search vendor "Foolabs" | Xpdf Search vendor "Foolabs" for product "Xpdf" | 0.93a Search vendor "Foolabs" for product "Xpdf" and version "0.93a" | - |
Affected
| ||||||
Foolabs Search vendor "Foolabs" | Xpdf Search vendor "Foolabs" for product "Xpdf" | 0.93b Search vendor "Foolabs" for product "Xpdf" and version "0.93b" | - |
Affected
| ||||||
Foolabs Search vendor "Foolabs" | Xpdf Search vendor "Foolabs" for product "Xpdf" | 0.93c Search vendor "Foolabs" for product "Xpdf" and version "0.93c" | - |
Affected
| ||||||
Foolabs Search vendor "Foolabs" | Xpdf Search vendor "Foolabs" for product "Xpdf" | 1.00a Search vendor "Foolabs" for product "Xpdf" and version "1.00a" | - |
Affected
| ||||||
Foolabs Search vendor "Foolabs" | Xpdf Search vendor "Foolabs" for product "Xpdf" | 3.0.1 Search vendor "Foolabs" for product "Xpdf" and version "3.0.1" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | <= 3.02 Search vendor "Glyphandcog" for product "Xpdfreader" and version " <= 3.02" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 0.2 Search vendor "Glyphandcog" for product "Xpdfreader" and version "0.2" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 0.3 Search vendor "Glyphandcog" for product "Xpdfreader" and version "0.3" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 0.4 Search vendor "Glyphandcog" for product "Xpdfreader" and version "0.4" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 0.5 Search vendor "Glyphandcog" for product "Xpdfreader" and version "0.5" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 0.6 Search vendor "Glyphandcog" for product "Xpdfreader" and version "0.6" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 0.7 Search vendor "Glyphandcog" for product "Xpdfreader" and version "0.7" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 0.80 Search vendor "Glyphandcog" for product "Xpdfreader" and version "0.80" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 0.90 Search vendor "Glyphandcog" for product "Xpdfreader" and version "0.90" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 0.91 Search vendor "Glyphandcog" for product "Xpdfreader" and version "0.91" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 0.92 Search vendor "Glyphandcog" for product "Xpdfreader" and version "0.92" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 0.93 Search vendor "Glyphandcog" for product "Xpdfreader" and version "0.93" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 1.00 Search vendor "Glyphandcog" for product "Xpdfreader" and version "1.00" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 1.01 Search vendor "Glyphandcog" for product "Xpdfreader" and version "1.01" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 2.00 Search vendor "Glyphandcog" for product "Xpdfreader" and version "2.00" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 2.01 Search vendor "Glyphandcog" for product "Xpdfreader" and version "2.01" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 2.02 Search vendor "Glyphandcog" for product "Xpdfreader" and version "2.02" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 2.03 Search vendor "Glyphandcog" for product "Xpdfreader" and version "2.03" | - |
Affected
| ||||||
Glyphandcog Search vendor "Glyphandcog" | Xpdfreader Search vendor "Glyphandcog" for product "Xpdfreader" | 3.00 Search vendor "Glyphandcog" for product "Xpdfreader" and version "3.00" | - |
Affected
|