5
CVSSv2

CVE-2009-0756

Published: 03/03/2009 Updated: 10/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The JBIG2Stream::readSymbolDictSeg function in Poppler prior to 0.10.4 allows remote malicious users to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and triggers an invalid memory dereference.

Vulnerable Product Search on Vulmon Subscribe to Product

poppler poppler 0.1

poppler poppler 0.1.1

poppler poppler 0.3.2

poppler poppler 0.5.91

poppler poppler 0.4.2

poppler poppler 0.4.3

poppler poppler 0.5.90

poppler poppler 0.5.9

poppler poppler

poppler poppler 0.3.0

poppler poppler 0.3.1

poppler poppler 0.7.0

poppler poppler 0.7.3

poppler poppler 0.5.1

poppler poppler 0.5.0

poppler poppler 0.4.4

poppler poppler 0.6.1

poppler poppler 0.6.0

poppler poppler 0.2.0

poppler poppler 0.10.1

poppler poppler 0.7.2

poppler poppler 0.6.4

poppler poppler 0.3.3

poppler poppler 0.5.2

poppler poppler 0.6.3

poppler poppler 0.6.2

poppler poppler 0.1.2

poppler poppler 0.10.2

poppler poppler 0.8.4

poppler poppler 0.7.1

poppler poppler 0.4.1

poppler poppler 0.4.0

poppler poppler 0.5.4

poppler poppler 0.5.3

Vendor Advisories

Debian Bug report logs - #518478 several crashes (DoS) Package: libpoppler5; Maintainer for libpoppler5 is (unknown); Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Fri, 6 Mar 2009 13:36:01 UTC Severity: important Tags: patch, security Found in version poppler/087-1 Fixed in version 0104-1 Done: Ja ...

Exploits

source: wwwsecurityfocuscom/bid/33749/info Poppler is prone to multiple denial-of-service vulnerabilities when handling malformed PDF files Successfully exploiting this issue allows remote attackers to crash applications that use the vulnerable library, denying service to legitimate users These issues affect versions prior to Poppler ...