Lucene search

K
cve[email protected]CVE-2009-0146
HistoryApr 23, 2009 - 5:30 p.m.

CVE-2009-0146

2009-04-2317:30:01
CWE-119
web.nvd.nist.gov
43
cve-2009-0146
buffer overflow
xpdf
cups
denial of service
remote attack
crafted pdf file

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

7.3 High

AI Score

Confidence

High

0.028 Low

EPSS

Percentile

90.7%

Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.

Affected configurations

NVD
Node
foolabsxpdfMatch0.5a
OR
foolabsxpdfMatch0.7a
OR
foolabsxpdfMatch0.91a
OR
foolabsxpdfMatch0.91b
OR
foolabsxpdfMatch0.91c
OR
foolabsxpdfMatch0.92a
OR
foolabsxpdfMatch0.92b
OR
foolabsxpdfMatch0.92c
OR
foolabsxpdfMatch0.92d
OR
foolabsxpdfMatch0.92e
OR
foolabsxpdfMatch0.93a
OR
foolabsxpdfMatch0.93b
OR
foolabsxpdfMatch0.93c
OR
foolabsxpdfMatch1.00a
OR
glyphandcogxpdfreaderRange3.02
OR
glyphandcogxpdfreaderMatch0.2
OR
glyphandcogxpdfreaderMatch0.3
OR
glyphandcogxpdfreaderMatch0.4
OR
glyphandcogxpdfreaderMatch0.5
OR
glyphandcogxpdfreaderMatch0.6
OR
glyphandcogxpdfreaderMatch0.7
OR
glyphandcogxpdfreaderMatch0.80
OR
glyphandcogxpdfreaderMatch0.90
OR
glyphandcogxpdfreaderMatch0.91
OR
glyphandcogxpdfreaderMatch0.92
OR
glyphandcogxpdfreaderMatch0.93
OR
glyphandcogxpdfreaderMatch1.00
OR
glyphandcogxpdfreaderMatch1.01
OR
glyphandcogxpdfreaderMatch2.00
OR
glyphandcogxpdfreaderMatch2.01
OR
glyphandcogxpdfreaderMatch2.02
OR
glyphandcogxpdfreaderMatch2.03
OR
glyphandcogxpdfreaderMatch3.00
OR
glyphandcogxpdfreaderMatch3.01
Node
applecupsRange1.3.9
OR
applecupsMatch1.1
OR
applecupsMatch1.1.1
OR
applecupsMatch1.1.2
OR
applecupsMatch1.1.3
OR
applecupsMatch1.1.4
OR
applecupsMatch1.1.5
OR
applecupsMatch1.1.5-1
OR
applecupsMatch1.1.5-2
OR
applecupsMatch1.1.6
OR
applecupsMatch1.1.6-1
OR
applecupsMatch1.1.6-2
OR
applecupsMatch1.1.6-3
OR
applecupsMatch1.1.7
OR
applecupsMatch1.1.8
OR
applecupsMatch1.1.9
OR
applecupsMatch1.1.9-1
OR
applecupsMatch1.1.10
OR
applecupsMatch1.1.10-1
OR
applecupsMatch1.1.11
OR
applecupsMatch1.1.12
OR
applecupsMatch1.1.13
OR
applecupsMatch1.1.14
OR
applecupsMatch1.1.15
OR
applecupsMatch1.1.16
OR
applecupsMatch1.1.17
OR
applecupsMatch1.1.18
OR
applecupsMatch1.1.19
OR
applecupsMatch1.1.19rc1
OR
applecupsMatch1.1.19rc2
OR
applecupsMatch1.1.19rc3
OR
applecupsMatch1.1.19rc4
OR
applecupsMatch1.1.19rc5
OR
applecupsMatch1.1.20
OR
applecupsMatch1.1.20rc1
OR
applecupsMatch1.1.20rc2
OR
applecupsMatch1.1.20rc3
OR
applecupsMatch1.1.20rc4
OR
applecupsMatch1.1.20rc5
OR
applecupsMatch1.1.20rc6
OR
applecupsMatch1.1.21
OR
applecupsMatch1.1.21rc1
OR
applecupsMatch1.1.21rc2
OR
applecupsMatch1.1.22
OR
applecupsMatch1.1.22rc1
OR
applecupsMatch1.1.22rc2
OR
applecupsMatch1.1.23
OR
applecupsMatch1.1.23rc1
OR
applecupsMatch1.2.0
OR
applecupsMatch1.2.1
OR
applecupsMatch1.2.2
OR
applecupsMatch1.2.3
OR
applecupsMatch1.2.4
OR
applecupsMatch1.2.5
OR
applecupsMatch1.2.6
OR
applecupsMatch1.2.7
OR
applecupsMatch1.2.8
OR
applecupsMatch1.2.9
OR
applecupsMatch1.2.10
OR
applecupsMatch1.2.11
OR
applecupsMatch1.2.12
OR
applecupsMatch1.3.0
OR
applecupsMatch1.3.1
OR
applecupsMatch1.3.2
OR
applecupsMatch1.3.3
OR
applecupsMatch1.3.4
OR
applecupsMatch1.3.5
OR
applecupsMatch1.3.6
OR
applecupsMatch1.3.7
OR
applecupsMatch1.3.8
OR
applecupsMatch1.3.10
OR
applecupsMatch1.3.11

References

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

7.3 High

AI Score

Confidence

High

0.028 Low

EPSS

Percentile

90.7%