// For flags

CVE-2009-3606

xpdf/poppler: PSOutputDev:: doImageL1Sep integer overflow

Severity Score

7.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.

Desbordamiento de entero en la función PSOutputDev::doImageL1Sep en Xpdf v3.02pl4 y Poppler v0.x, usado en n kdegraphics KPDF, podría permitir a atacantes remotos la ejecución de código de su elección a través de un documento PDF manipulado que provoca un desbordamiento de búfer basado en memoria dinámica (heap).

Multiple security vulnerabilities has been discovered and corrected in poppler. An out-of-bounds reading flaw in the JBIG2 decoder allows remote attackers to cause a denial of service via a crafted PDF file. Multiple input validation flaws in the JBIG2 decoder allows remote attackers to execute arbitrary code via a crafted PDF file. An integer overflow in the JBIG2 decoder allows remote attackers to execute arbitrary code via a crafted PDF file. Multiple other vulnerabilities have been addressed as well. The updated packages have been patched to correct these issues.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
Attack Vector
Local
Attack Complexity
High
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-10-09 CVE Reserved
  • 2009-10-21 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-189: Numeric Errors
  • CWE-190: Integer Overflow or Wraparound
CAPEC
References (43)
URL Date SRC
http://www.securityfocus.com/bid/36703 2024-08-07
URL Date SRC
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035340.html 2023-02-13
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035399.html 2023-02-13
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035408.html 2023-02-13
http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html 2023-02-13
http://secunia.com/advisories/37023 2023-02-13
http://secunia.com/advisories/37037 2023-02-13
http://secunia.com/advisories/37042 2023-02-13
http://secunia.com/advisories/37043 2023-02-13
http://secunia.com/advisories/37053 2023-02-13
http://secunia.com/advisories/37077 2023-02-13
http://sunsolve.sun.com/search/document.do?assetkey=1-66-274030-1 2023-02-13
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021706.1-1 2023-02-13
http://www.debian.org/security/2009/dsa-1941 2023-02-13
http://www.debian.org/security/2010/dsa-2028 2023-02-13
http://www.debian.org/security/2010/dsa-2050 2023-02-13
http://www.mandriva.com/security/advisories?name=MDVSA-2009:287 2023-02-13
http://www.mandriva.com/security/advisories?name=MDVSA-2010:087 2023-02-13
http://www.mandriva.com/security/advisories?name=MDVSA-2011:175 2023-02-13
https://bugzilla.redhat.com/show_bug.cgi?id=526877 2009-10-15
https://rhn.redhat.com/errata/RHSA-2009-1500.html 2023-02-13
https://rhn.redhat.com/errata/RHSA-2009-1501.html 2023-02-13
https://rhn.redhat.com/errata/RHSA-2009-1502.html 2023-02-13
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00750.html 2023-02-13
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00784.html 2023-02-13
https://access.redhat.com/security/cve/CVE-2009-3606 2009-10-15
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Foolabs
Search vendor "Foolabs"
Xpdf
Search vendor "Foolabs" for product "Xpdf"
3.02pl1
Search vendor "Foolabs" for product "Xpdf" and version "3.02pl1"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Foolabs
Search vendor "Foolabs"
Xpdf
Search vendor "Foolabs" for product "Xpdf"
3.02pl2
Search vendor "Foolabs" for product "Xpdf" and version "3.02pl2"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Foolabs
Search vendor "Foolabs"
Xpdf
Search vendor "Foolabs" for product "Xpdf"
3.02pl3
Search vendor "Foolabs" for product "Xpdf" and version "3.02pl3"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Glyphandcog
Search vendor "Glyphandcog"
Xpdfreader
Search vendor "Glyphandcog" for product "Xpdfreader"
3.00
Search vendor "Glyphandcog" for product "Xpdfreader" and version "3.00"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Glyphandcog
Search vendor "Glyphandcog"
Xpdfreader
Search vendor "Glyphandcog" for product "Xpdfreader"
3.01
Search vendor "Glyphandcog" for product "Xpdfreader" and version "3.01"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Glyphandcog
Search vendor "Glyphandcog"
Xpdfreader
Search vendor "Glyphandcog" for product "Xpdfreader"
3.02
Search vendor "Glyphandcog" for product "Xpdfreader" and version "3.02"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.1
Search vendor "Poppler" for product "Poppler" and version "0.1"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.1.1
Search vendor "Poppler" for product "Poppler" and version "0.1.1"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.1.2
Search vendor "Poppler" for product "Poppler" and version "0.1.2"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.2.0
Search vendor "Poppler" for product "Poppler" and version "0.2.0"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.3.0
Search vendor "Poppler" for product "Poppler" and version "0.3.0"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.3.1
Search vendor "Poppler" for product "Poppler" and version "0.3.1"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.3.2
Search vendor "Poppler" for product "Poppler" and version "0.3.2"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.3.3
Search vendor "Poppler" for product "Poppler" and version "0.3.3"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.4.0
Search vendor "Poppler" for product "Poppler" and version "0.4.0"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.4.1
Search vendor "Poppler" for product "Poppler" and version "0.4.1"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.4.2
Search vendor "Poppler" for product "Poppler" and version "0.4.2"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.4.3
Search vendor "Poppler" for product "Poppler" and version "0.4.3"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.4.4
Search vendor "Poppler" for product "Poppler" and version "0.4.4"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.5.0
Search vendor "Poppler" for product "Poppler" and version "0.5.0"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.5.1
Search vendor "Poppler" for product "Poppler" and version "0.5.1"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.5.2
Search vendor "Poppler" for product "Poppler" and version "0.5.2"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.5.3
Search vendor "Poppler" for product "Poppler" and version "0.5.3"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.5.4
Search vendor "Poppler" for product "Poppler" and version "0.5.4"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.5.9
Search vendor "Poppler" for product "Poppler" and version "0.5.9"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.6.0
Search vendor "Poppler" for product "Poppler" and version "0.6.0"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.6.1
Search vendor "Poppler" for product "Poppler" and version "0.6.1"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.6.2
Search vendor "Poppler" for product "Poppler" and version "0.6.2"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.6.3
Search vendor "Poppler" for product "Poppler" and version "0.6.3"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.6.4
Search vendor "Poppler" for product "Poppler" and version "0.6.4"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.7.0
Search vendor "Poppler" for product "Poppler" and version "0.7.0"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.7.1
Search vendor "Poppler" for product "Poppler" and version "0.7.1"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.7.2
Search vendor "Poppler" for product "Poppler" and version "0.7.2"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.7.3
Search vendor "Poppler" for product "Poppler" and version "0.7.3"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.8.0
Search vendor "Poppler" for product "Poppler" and version "0.8.0"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.8.1
Search vendor "Poppler" for product "Poppler" and version "0.8.1"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.8.2
Search vendor "Poppler" for product "Poppler" and version "0.8.2"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.8.3
Search vendor "Poppler" for product "Poppler" and version "0.8.3"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.8.4
Search vendor "Poppler" for product "Poppler" and version "0.8.4"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.8.6
Search vendor "Poppler" for product "Poppler" and version "0.8.6"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.8.7
Search vendor "Poppler" for product "Poppler" and version "0.8.7"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.9.0
Search vendor "Poppler" for product "Poppler" and version "0.9.0"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.9.1
Search vendor "Poppler" for product "Poppler" and version "0.9.1"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.9.2
Search vendor "Poppler" for product "Poppler" and version "0.9.2"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.9.3
Search vendor "Poppler" for product "Poppler" and version "0.9.3"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.10.0
Search vendor "Poppler" for product "Poppler" and version "0.10.0"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.10.1
Search vendor "Poppler" for product "Poppler" and version "0.10.1"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.10.2
Search vendor "Poppler" for product "Poppler" and version "0.10.2"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.10.3
Search vendor "Poppler" for product "Poppler" and version "0.10.3"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.10.4
Search vendor "Poppler" for product "Poppler" and version "0.10.4"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.10.5
Search vendor "Poppler" for product "Poppler" and version "0.10.5"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.10.6
Search vendor "Poppler" for product "Poppler" and version "0.10.6"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.10.7
Search vendor "Poppler" for product "Poppler" and version "0.10.7"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.11.0
Search vendor "Poppler" for product "Poppler" and version "0.11.0"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.11.1
Search vendor "Poppler" for product "Poppler" and version "0.11.1"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.11.2
Search vendor "Poppler" for product "Poppler" and version "0.11.2"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.11.3
Search vendor "Poppler" for product "Poppler" and version "0.11.3"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.12.0
Search vendor "Poppler" for product "Poppler" and version "0.12.0"
-
Affected
in Kde
Search vendor "Kde"
Kpdf
Search vendor "Kde" for product "Kpdf"
*-
Safe