9.3
CVSSv2

CVE-2009-3607

Published: 21/10/2009 Updated: 07/11/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer overflow in the create_surface_from_thumbnail_data function in glib/poppler-page.cc in Poppler 0.x allows remote malicious users to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

poppler poppler 0.7.3

poppler poppler 0.3.2

poppler poppler 0.10.3

poppler poppler 0.4.0

poppler poppler 0.8.5

poppler poppler 0.9.3

poppler poppler 0.10.1

poppler poppler 0.10.0

poppler poppler 0.10.7

poppler poppler 0.7.1

poppler poppler 0.6.1

poppler poppler 0.3.1

poppler poppler 0.11.3

poppler poppler 0.10.6

poppler poppler 0.5.2

poppler poppler 0.5.91

poppler poppler 0.6.0

poppler poppler 0.3.3

poppler poppler 0.4.2

poppler poppler 0.10.4

poppler poppler 0.9.2

poppler poppler 0.6.4

poppler poppler 0.1.2

poppler poppler 0.8.0

poppler poppler 0.11.2

poppler poppler 0.8.3

poppler poppler 0.7.0

poppler poppler 0.12.0

poppler poppler 0.7.2

poppler poppler 0.5.0

poppler poppler 0.8.6

poppler poppler 0.5.9

poppler poppler 0.5.90

poppler poppler 0.6.3

poppler poppler 0.2.0

poppler poppler 0.8.4

poppler poppler 0.5.4

poppler poppler 0.1.1

poppler poppler 0.9.0

poppler poppler 0.4.1

poppler poppler 0.5.3

poppler poppler 0.4.4

poppler poppler 0.8.7

poppler poppler 0.9.1

poppler poppler 0.3.0

poppler poppler 0.11.0

poppler poppler 0.1

poppler poppler 0.6.2

poppler poppler 0.10.2

poppler poppler 0.4.3

poppler poppler 0.8.1

poppler poppler 0.5.1

poppler poppler 0.8.2

poppler poppler 0.11.1

poppler poppler 0.10.5

Vendor Advisories

USN-850-1 fixed vulnerabilities in poppler This update provides the corresponding updates for Ubuntu 910 ...
It was discovered that poppler contained multiple security issues when parsing malformed PDF documents If a user or automated system were tricked into opening a crafted PDF file, an attacker could cause a denial of service or execute arbitrary code with privileges of the user invoking the program ...