// For flags

CVE-2009-3050

 

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.cxx and ps-pdf.cxx using an AFM font file with a long glyph name, but these vectors do not cross privilege boundaries.

Desbordamiento de búfer en la función set_page_size en util.cxx en HTMLDOC 1.8.27 y versiones anteriores permite a atacantes dependientes de contexto ejecutar código de su elección mediante un comentario MEDIA SIZE largo. NOTA: más tarde se informó que había vectores adicionales en htmllib.cxx y ps-pdf.cxx utilizando un archivo de fuentes AFM con un nombre glyph largo, pero estos vectores no traspasan la frontera de privilegios.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-09-02 CVE Reserved
  • 2009-09-02 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-17 EPSS Updated
  • 2024-09-17 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Htmldoc
Search vendor "Htmldoc"
Htmldoc
Search vendor "Htmldoc" for product "Htmldoc"
<= 1.8.27
Search vendor "Htmldoc" for product "Htmldoc" and version " <= 1.8.27"
-
Affected
Htmldoc
Search vendor "Htmldoc"
Htmldoc
Search vendor "Htmldoc" for product "Htmldoc"
1.8.24
Search vendor "Htmldoc" for product "Htmldoc" and version "1.8.24"
-
Affected
Htmldoc
Search vendor "Htmldoc"
Htmldoc
Search vendor "Htmldoc" for product "Htmldoc"
1.8.25
Search vendor "Htmldoc" for product "Htmldoc" and version "1.8.25"
-
Affected
Htmldoc
Search vendor "Htmldoc"
Htmldoc
Search vendor "Htmldoc" for product "Htmldoc"
1.8.26
Search vendor "Htmldoc" for product "Htmldoc" and version "1.8.26"
-
Affected