5
CVSSv2

CVE-2009-1187

Published: 23/04/2009 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Integer overflow in the JBIG2 decoding feature in Poppler prior to 0.10.6 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to CairoOutputDev (CairoOutputDev.cc).

Vulnerable Product Search on Vulmon Subscribe to Product

poppler poppler 0.7.3

poppler poppler 0.3.2

poppler poppler 0.10.3

poppler poppler 0.4.0

poppler poppler 0.8.5

poppler poppler 0.9.3

poppler poppler 0.10.1

poppler poppler 0.10.0

poppler poppler 0.7.1

poppler poppler 0.6.1

poppler poppler 0.3.1

poppler poppler 0.5.2

poppler poppler 0.5.91

poppler poppler 0.6.0

poppler poppler 0.3.3

poppler poppler 0.4.2

poppler poppler 0.10.4

poppler poppler 0.9.2

poppler poppler 0.6.4

poppler poppler 0.1.2

poppler poppler 0.8.0

poppler poppler 0.8.3

poppler poppler 0.7.0

poppler poppler 0.7.2

poppler poppler 0.5.0

poppler poppler 0.8.6

poppler poppler 0.5.9

poppler poppler 0.5.90

poppler poppler 0.6.3

poppler poppler 0.2.0

poppler poppler 0.8.4

poppler poppler 0.5.4

poppler poppler 0.1.1

poppler poppler 0.9.0

poppler poppler 0.4.1

poppler poppler 0.5.3

poppler poppler

poppler poppler 0.4.4

poppler poppler 0.8.7

poppler poppler 0.9.1

poppler poppler 0.3.0

poppler poppler 0.1

poppler poppler 0.6.2

poppler poppler 0.10.2

poppler poppler 0.4.3

poppler poppler 0.8.1

poppler poppler 0.5.1

poppler poppler 0.8.2

Vendor Advisories

Synopsis Important: poppler security update Type/Severity Security Advisory: Important Topic Updated poppler packages that fix multiple security issues are nowavailable for Red Hat Enterprise Linux 5This update has been rated as having important security impact by the RedHat Security Response Team ...
Debian Bug report logs - #524806 poppler: multiple vulnerabilities Package: poppler; Maintainer for poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Mon, 20 Apr 2009 02:06:01 UTC Severity: grave T ...
Will Dormann, Alin Rad Pop, Braden Thomas, and Drew Yao discovered that poppler contained multiple security issues in its JBIG2 decoder If a user or automated system were tricked into opening a crafted PDF file, an attacker could cause a denial of service or execute arbitrary code with privileges of the user invoking the program ...