6.8
CVSSv2

CVE-2009-0791

Published: 09/06/2009 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1) Decrypt.cxx, (2) FoFiTrueType.cxx, (3) gmem.c, (4) JBIG2Stream.cxx, and (5) PSOutputDev.cxx in pdftops/. NOTE: the JBIG2Stream.cxx vector may overlap CVE-2009-1179.

Vulnerable Product Search on Vulmon Subscribe to Product

apple cups 1.1.22

apple cups 1.1.17

apple cups 1.3.7

Vendor Advisories

Debian Bug report logs - #535488 cupsys: CVE-2009-0791 integer overflow vulnerabilities Package: cupsys; Maintainer for cupsys is (unknown); Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Thu, 2 Jul 2009 16:39:02 UTC Severity: serious Tags: patch, security Found in version cupsys/127-4etch6 Done ...
Synopsis Important: poppler security update Type/Severity Security Advisory: Important Topic Updated poppler packages that fix multiple security issues are nowavailable for Red Hat Enterprise Linux 5This update has been rated as having important security impact by the RedHat Security Response Team ...
Synopsis Important: cups security update Type/Severity Security Advisory: Important Topic Updated cups packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 3 and 4This update has been rated as having important security impact by the RedHat Security Response Team ...