CVE-2009-0690
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a negative value for the stream offset in a JPEG2000 (aka JPX) stream, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted PDF file that triggers an out-of-bounds read.
El complemento Foxit JPEG2000/JBIG2 Decoder antes de v2.0.2009.616 para Foxit Reader 3.0 antes de Build1817 no gestiona correctamente un valor negativo para la posición del octeto del stream en un flujo JPEG2000 (alias JPX), lo que permite a atacantes remotos provocar una denegación de servicio (mediante corrupción memoria y bloqueo de la aplicación) o posiblemente ejecutar código arbitrario a través de un archivo PDF modificado que provoca una lectura fuera de límite.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-02-22 CVE Reserved
- 2009-06-23 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://securitytracker.com/id?1022425 | Vdb Entry | |
http://www.kb.cert.org/vuls/id/251793 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.foxitsoftware.com/pdf/reader/security.htm#0602 | 2009-06-24 | |
http://www.securityfocus.com/bid/35442 | 2009-06-24 | |
http://www.vupen.com/english/advisories/2009/1640 | 2009-06-24 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/35512 | 2009-06-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Foxitsoftware Search vendor "Foxitsoftware" | Foxit Reader Search vendor "Foxitsoftware" for product "Foxit Reader" | 3.0 Search vendor "Foxitsoftware" for product "Foxit Reader" and version "3.0" | - |
Affected
| in | Foxitsoftware Search vendor "Foxitsoftware" | Jpeg2000\/jbig2 Decoder Add-on Search vendor "Foxitsoftware" for product "Jpeg2000\/jbig2 Decoder Add-on" | 2.0.2009.303 Search vendor "Foxitsoftware" for product "Jpeg2000\/jbig2 Decoder Add-on" and version "2.0.2009.303" | - |
Affected
|
Foxitsoftware Search vendor "Foxitsoftware" | Foxit Reader Search vendor "Foxitsoftware" for product "Foxit Reader" | 3.0.2009.1301 Search vendor "Foxitsoftware" for product "Foxit Reader" and version "3.0.2009.1301" | - |
Affected
| in | Foxitsoftware Search vendor "Foxitsoftware" | Jpeg2000\/jbig2 Decoder Add-on Search vendor "Foxitsoftware" for product "Jpeg2000\/jbig2 Decoder Add-on" | 2.0.2009.303 Search vendor "Foxitsoftware" for product "Jpeg2000\/jbig2 Decoder Add-on" and version "2.0.2009.303" | - |
Affected
|